Vulnerability Name: | CVE-2022-32912 (CCN-235748) | ||||||||||||||||||||||||
Assigned: | 2022-09-12 | ||||||||||||||||||||||||
Published: | 2022-09-12 | ||||||||||||||||||||||||
Updated: | 2022-12-07 | ||||||||||||||||||||||||
Summary: | Apple Safari could allow a remote attacker to execute arbitrary code on the system, caused by an out-of-bounds read in the WebKit component. By persuading a victim to open a specially-crafted web content, an attacker could exploit this vulnerability to execute arbitrary code on the system. | ||||||||||||||||||||||||
CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) 7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
7.7 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 9.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C)
| ||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2022-32912 Source: product-security@apple.com Type: Mailing List, Third Party Advisory product-security@apple.com Source: product-security@apple.com Type: Mailing List, Third Party Advisory product-security@apple.com Source: product-security@apple.com Type: Mailing List, Third Party Advisory product-security@apple.com Source: product-security@apple.com Type: Mailing List, Third Party Advisory product-security@apple.com Source: product-security@apple.com Type: Mailing List, Third Party Advisory product-security@apple.com Source: product-security@apple.com Type: Mailing List, Third Party Advisory product-security@apple.com Source: product-security@apple.com Type: Mailing List, Third Party Advisory product-security@apple.com Source: XF Type: UNKNOWN apple-safari-cve202232912-code-exec(235748) Source: CCN Type: Apple security document HT213442 About the security content of Safari 16 Source: product-security@apple.com Type: Release Notes, Vendor Advisory product-security@apple.com Source: product-security@apple.com Type: Release Notes, Vendor Advisory product-security@apple.com Source: CCN Type: Apple security document HT213446 About the security content of iOS 16 Source: product-security@apple.com Type: Release Notes, Vendor Advisory product-security@apple.com Source: CCN Type: Mend Vulnerability Database CVE-2022-32912 | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |