ZeroHour

CVE-2022-32893

KEVmass

Out-of-Bounds Write in Apple WebKit (iOS/macOS/Safari) Enables RCE

CISA: Apple iOS and macOS Out-of-Bounds Write Vulnerability

CVSS 3.1
8.8 high
EPSS
10%p95
Published
()
KEV added
AI analysis

CVE-2022-32893 is an out-of-bounds write flaw (CWE-787) in Apple's WebKit browser engine, caused by insufficient bounds checking. It is triggered when a device processes maliciously crafted web content, meaning a user can be attacked simply by loading an attacker-controlled webpage. A successful exploit allows arbitrary code execution on the victim's device, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8). Affected users include anyone running iOS/iPadOS before 15.6.1, macOS Monterey before 12.5.1, or Safari before 15.6.1, as well as consumers of WebKitGTK and WPE WebKit shipped in Fedora and Debian. Apple confirmed the issue was being actively exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-08-18; EPSS estimates a 9.9% probability of exploitation in the next 30 days (95th percentile), while no public PoC is known.

What to do: Immediately update to iOS 15.6.1, iPadOS 15.6.1, macOS Monterey 12.5.1, and Safari 15.6.1; per vendor reporting, Apple also released updates for older iPhone models, and users of devices running the iOS 15.7 beta should apply 15.6.1. Fedora and Debian users should install the patched WebKitGTK/WPE WebKit packages from their distribution's advisories. Because exploitation requires only loading malicious web content, there is no reliable workaround — prioritize patching on all endpoints that browse web content, and treat unpatched Apple devices as actively targeted.

Affected
Apple iPhone OS (iOS)all versions prior to 15.6.1
Apple iPadOSall versions prior to 15.6.1
Apple macOS Montereyprior to 12.5.1
Apple Safariprior to 15.6.1
WebKitGTK project WebKitGTK
WPE WebKit project WPE WebKit
Fedora Project Fedora Linux (WebKitGTK/WPE WebKit packages)versions shipping the affected WebKit code; see Fedora advisories
Debian Linux (WebKitGTK/WPE WebKit packages)versions shipping the affected WebKit code; see Debian advisories
Estimated exposure
masshundreds of millions of devices (Apple's active iPhone/Mac installed base plus Safari/WebKit users) — Apple's active installed base has publicly exceeded one billion iPhones plus hundreds of millions of Macs, and WebKitGTK/WPE WebKit ship in Fedora and Debian, so the population of unpatched devices at disclosure was plausibly in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CISA Known Exploited Vulnerability
Affected
Apple iOS and macOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
applefedoraprojectdebianwebkitgtkwpewebkit
Products
safari, ipados, iphone os, macos, fedora, debian linux, webkitgtk, wpe webkit
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news