CVE-2022-32833

MEDIUM

Safari < 16.0 - Unprotected User Data Exposure via Path Handling Issue

Title source: llm
STIX 2.1

Description

An issue existed with the file paths used to store website data. The issue was resolved by improving how website data is stored. This issue is fixed in iOS 16. An unauthorized user may be able to access browsing history.

References (3)

Core 3
Core References
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213446
Release Notes, Vendor Advisory
https://support.apple.com/kb/HT213442
Release Notes, Vendor Advisory
https://support.apple.com/kb/HT213488

Scores

CVSS v3 5.3
EPSS 0.0062
EPSS Percentile 44.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-922
Status published
Products (3)
apple/iphone_os < 16.0
apple/macos < 13.0
apple/safari < 16.0
Published Dec 15, 2022
Tracked Since Feb 18, 2026