CVE-2022-32862

MEDIUM

Apple Macos < 11.7.1 - Information Disclosure

Title source: rule
STIX 2.1

Description

This issue was addressed with improved data protection. This issue is fixed in macOS Big Sur 11.7.1, macOS Ventura 13, macOS Monterey 12.6.1. An app with root privileges may be able to access private information.

Exploits (1)

nomisec WORKING POC
by rohitc33 · poc
https://github.com/rohitc33/CVE-2022-32862

References (3)

Core 3
Core References
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213488
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213493
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213494

Scores

CVSS v3 5.5
EPSS 0.0300
EPSS Percentile 86.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
apple/macos 11.0 - 11.7.1
Published Nov 01, 2022
Tracked Since Feb 18, 2026