VYPR
Unrated severityNVD Advisory· Published Sep 23, 2022· Updated May 22, 2025

CVE-2022-32799

CVE-2022-32799

Description

An out-of-bounds read issue was addressed with improved bounds checking. This issue is fixed in Security Update 2022-005 Catalina, macOS Monterey 12.5. A user in a privileged network position may be able to leak sensitive information.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An out-of-bounds read in macOS Monterey 12.5 and Security Update 2022-005 Catalina could allow a privileged network attacker to leak sensitive information.

Vulnerability

CVE-2022-32799 is an out-of-bounds read issue present in macOS Monterey 12.5 and earlier, as well as in macOS Catalina prior to Security Update 2022-005. The vulnerability resides in a component that parses network traffic; insufficient bounds checking allows reading beyond the intended buffer boundaries. The issue is fixed in macOS Monterey 12.5 and Security Update 2022-005 Catalina [1][2].

Exploitation

Exploitation requires that the attacker be in a privileged network position (e.g., on the same subnet or able to perform man-in-the-middle attacks). The attacker can craft a malicious network packet that triggers the out-of-bounds read when processed by the vulnerable component on the target system. No user interaction is needed beyond the target receiving the packet over the network.

Impact

Successful exploitation may leak sensitive information from kernel or system memory, as stated in the official description: "A user in a privileged network position may be able to leak sensitive information." The exact nature of the leaked data is not specified, but it could include cryptographic keys, credentials, or other confidential data that an attacker could use to further compromise the system.

Mitigation

Apple released fixes on July 20, 2022, in macOS Monterey 12.5 and Security Update 2022-005 for Catalina. Users should update to the latest available version. There is no known workaround. The vulnerability was not listed in CISA's Known Exploited Vulnerabilities catalog as of publication.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.