CVE-2022-32893
KEVmassOut-of-Bounds Write in Apple WebKit (iOS/macOS/Safari) Enables RCE
CISA: Apple iOS and macOS Out-of-Bounds Write Vulnerability
CVE-2022-32893 is an out-of-bounds write flaw (CWE-787) in Apple's WebKit browser engine, caused by insufficient bounds checking. It is triggered when a device processes maliciously crafted web content, meaning a user can be attacked simply by loading an attacker-controlled webpage. A successful exploit allows arbitrary code execution on the victim's device, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8). Affected users include anyone running iOS/iPadOS before 15.6.1, macOS Monterey before 12.5.1, or Safari before 15.6.1, as well as consumers of WebKitGTK and WPE WebKit shipped in Fedora and Debian. Apple confirmed the issue was being actively exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-08-18; EPSS estimates a 9.9% probability of exploitation in the next 30 days (95th percentile), while no public PoC is known.
What to do: Immediately update to iOS 15.6.1, iPadOS 15.6.1, macOS Monterey 12.5.1, and Safari 15.6.1; per vendor reporting, Apple also released updates for older iPhone models, and users of devices running the iOS 15.7 beta should apply 15.6.1. Fedora and Debian users should install the patched WebKitGTK/WPE WebKit packages from their distribution's advisories. Because exploitation requires only loading malicious web content, there is no reliable workaround — prioritize patching on all endpoints that browse web content, and treat unpatched Apple devices as actively targeted.
| Apple iPhone OS (iOS) | all versions prior to 15.6.1 |
| Apple iPadOS | all versions prior to 15.6.1 |
| Apple macOS Monterey | prior to 12.5.1 |
| Apple Safari | prior to 15.6.1 |
| WebKitGTK project WebKitGTK | — |
| WPE WebKit project WPE WebKit | — |
| Fedora Project Fedora Linux (WebKitGTK/WPE WebKit packages) | versions shipping the affected WebKit code; see Fedora advisories |
| Debian Linux (WebKitGTK/WPE WebKit packages) | versions shipping the affected WebKit code; see Debian advisories |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
- Affected
- Apple iOS and macOS
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- applefedoraprojectdebianwebkitgtkwpewebkit
- Products
- safari, ipados, iphone os, macos, fedora, debian linux, webkitgtk, wpe webkit
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H