ZeroHour

CVE-2022-48503

KEVmass

Apple Web Content Bounds-Check Flaw Enables Code Execution Across iOS, macOS, Safari

CISA: Apple Multiple Products Unspecified Vulnerability

CVSS 3.1
8.8 high
EPSS
3%p88
Published
()
KEV added
AI analysis

CVE-2022-48503 is a bounds-checking flaw (CWE-129, improper validation of array index) in the web content processing engine used by Safari and by web views across Apple platforms, rated 8.8 (High) with a network attack vector and user interaction required. An attacker triggers it by getting a victim to process maliciously crafted web content, typically by visiting a hostile webpage, and gains arbitrary code execution in the context of the application rendering that content. Anyone running Safari or iOS, iPadOS, macOS Monterey, tvOS, or watchOS versions prior to the fixed releases (iOS/iPadOS 15.6, macOS Monterey 12.5, Safari 15.6, tvOS 15.6, watchOS 8.7) is affected, with older devices that cannot upgrade at greatest risk. CISA added the bug to its Known Exploited Vulnerabilities catalog on 2025-10-20, confirming exploitation in the wild, and October 2025 reporting on the Coruna iOS exploit kit describes exploit chains being used against older iOS versions. EPSS currently assigns a 3.2% probability of exploitation in the next 30 days (87th percentile); ransomware use is unknown.

What to do: Update affected devices to iOS/iPadOS 15.6 or later, macOS Monterey 12.5 or later, Safari 15.6 or later, tvOS 15.6 or later, and watchOS 8.7 or later; for older devices that cannot run these versions, apply Apple's emergency fixes for older iOS releases as reported in recent advisories. Federal agencies must apply vendor mitigations per BOD 22-01 guidance or discontinue use of affected products if mitigations are unavailable. Inventory managed Apple fleets for OS/Safari versions below the fixed releases and treat unpatched devices' web browsing as an unauthenticated code-execution risk until patched.

Affected
Apple iPhone OS (iOS)Versions before iOS 15.6; fixed in iOS 15.6
Apple iPadOSVersions before iPadOS 15.6; fixed in iPadOS 15.6
Apple macOS (Monterey)macOS Monterey versions before 12.5; fixed in macOS Monterey 12.5
Apple SafariVersions before Safari 15.6; fixed in Safari 15.6
Apple tvOSVersions before tvOS 15.6; fixed in tvOS 15.6
Apple watchOSVersions before watchOS 8.7; fixed in watchOS 8.7
Estimated exposure
masshundreds of millions of Apple devices worldwide on pre-fix OS or Safari versions — Apple's global installed base of active iPhones, iPads, Macs, Apple TVs, and Apple Watches runs to roughly a billion-plus devices and Safari is the default macOS browser, so the population still on versions older than the listed fixes —…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing web content may lead to arbitrary code execution.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
apple
Products
safari, ipados, iphone os, macos, tvos, watchos
Weakness
CWE-129
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news