CVE-2022-32913
Description
The issue was addressed with additional restrictions on the observability of app states. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, watchOS 9, macOS Monterey 12.6, tvOS 16. A sandboxed app may be able to determine which app is currently using the camera.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A sandboxed app on Apple platforms could determine which app is using the camera, violating privacy restrictions.
Vulnerability
The vulnerability resides in the observability of app states, allowing a sandboxed app to infer which app is currently using the camera. This affects macOS Big Sur before 11.7, macOS Monterey before 12.6, macOS Ventura before 13, iOS before 16, watchOS before 9, and tvOS before 16 [1][2][3][4].
Exploitation
An attacker requires a sandboxed app installed on the device. No additional privileges or user interaction beyond running the app are needed. The app can query system state to determine camera usage by another app, exploiting the insufficient restrictions on state observability.
Impact
Successful exploitation results in information disclosure: the attacker learns which app is currently using the camera. This violates user privacy but does not allow code execution, data modification, or access to camera content itself.
Mitigation
Apple addressed the issue by adding additional restrictions on app state observability. Fixed versions include macOS Big Sur 11.7, macOS Monterey 12.6, macOS Ventura 13, iOS 16, watchOS 9, and tvOS 16, released on September 12, 2022 (most platforms) and October 24, 2022 (macOS Ventura 13) [1][2][3][4]. Users should update to the latest available OS version; no workarounds are documented.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
5- Range: <16
- Range: <11.7
- Range: <13
- Range: unspecified
- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6News mentions
0No linked articles in our index yet.