High severity8.8CISA KEVNVD Advisory· Published Aug 24, 2022· Updated Jun 17, 2026
CVE-2022-32893
CVE-2022-32893
Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
49cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*range: <15.6.1
- (no CPE)range: Safari 15.6.1
- (no CPE)range: unspecified
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*range: <15.6.1
- (no CPE)range: iPadOS 15.6.1
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*range: >=12.0,<12.5.1
- (no CPE)range: unspecified
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
- Range: macOS Monterey 12.5.1
- Range: iOS 15.6.1
- osv-coords32 versionspkg:rpm/almalinux/webkit2gtk3pkg:rpm/almalinux/webkit2gtk3-develpkg:rpm/almalinux/webkit2gtk3-jscpkg:rpm/almalinux/webkit2gtk3-jsc-develpkg:rpm/opensuse/webkit2gtk3&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/webkit2gtk3&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/webkit2gtk3-soup2&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/webkit2gtk4&distro=openSUSE%20Leap%2015.4pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP3pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP4pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/webkit2gtk3&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/webkit2gtk3&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209pkg:rpm/suse/webkit2gtk3-soup2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4pkg:rpm/suse/webkit2gtk4&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP4
< 2.36.7-1.el8_6+ 31 more
- (no CPE)range: < 2.36.7-1.el8_6
- (no CPE)range: < 2.36.7-1.el8_6
- (no CPE)range: < 2.36.7-1.el8_6
- (no CPE)range: < 2.36.7-1.el8_6
- (no CPE)range: < 2.36.7-150200.44.1
- (no CPE)range: < 2.36.7-150400.4.12.1
- (no CPE)range: < 2.36.7-150400.4.12.1
- (no CPE)range: < 2.36.7-150400.4.12.1
- (no CPE)range: < 2.36.7-150000.3.112.2
- (no CPE)range: < 2.36.7-150000.3.112.2
- (no CPE)range: < 2.36.7-150000.3.112.2
- (no CPE)range: < 2.36.7-150000.3.112.2
- (no CPE)range: < 2.36.7-150000.3.112.2
- (no CPE)range: < 2.36.7-150200.44.1
- (no CPE)range: < 2.36.7-150200.44.1
- (no CPE)range: < 2.36.7-150400.4.12.1
- (no CPE)range: < 2.36.7-2.110.1
- (no CPE)range: < 2.36.7-2.110.1
- (no CPE)range: < 2.36.7-2.110.1
- (no CPE)range: < 2.36.7-2.110.1
- (no CPE)range: < 2.36.7-150000.3.112.2
- (no CPE)range: < 2.36.7-150000.3.112.2
- (no CPE)range: < 2.36.7-150000.3.112.2
- (no CPE)range: < 2.36.7-2.110.1
- (no CPE)range: < 2.36.7-2.110.1
- (no CPE)range: < 2.36.7-150000.3.112.2
- (no CPE)range: < 2.36.7-150000.3.112.2
- (no CPE)range: < 2.36.7-2.110.1
- (no CPE)range: < 2.36.7-2.110.1
- (no CPE)range: < 2.36.7-2.110.1
- (no CPE)range: < 2.36.7-150400.4.12.1
- (no CPE)range: < 2.36.7-150400.4.12.1
- Range: unspecified
Patches
Vulnerability mechanics
References
18- seclists.org/fulldisclosure/2022/Aug/16nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2022/Oct/49nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2022/08/25/5nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2022/08/26/2nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2022/08/29/1nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2022/08/29/2nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2022/09/02/10nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2022/09/13/1nvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2022/08/msg00019.htmlnvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/202208-39nvdThird Party Advisory
- support.apple.com/en-us/HT213412nvdVendor Advisory
- support.apple.com/en-us/HT213413nvdVendor Advisory
- support.apple.com/en-us/HT213414nvdVendor Advisory
- www.debian.org/security/2022/dsa-5219nvdMailing ListThird Party Advisory
- www.debian.org/security/2022/dsa-5220nvdMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7SETAAXEPGNBMYKTUDFEZHS5LGSQ64QL/nvdBroken Link
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YKJGV2EXVMYQW3OAJNI4WUTKKVMD2YYK/nvdBroken Link
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.