CVE-2022-32863

CRITICAL

Safari < 15.6 - Remote Code Execution via Memory Corruption

Title source: llm
STIX 2.1

Description

A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 15.6, macOS Monterey 12.5. Processing maliciously crafted web content may lead to arbitrary code execution.

References (3)

Core 3
Core References
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213341
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213345

Scores

CVSS v3 9.8
EPSS 0.0107
EPSS Percentile 78.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (2)
apple/macos 12.0.0 - 12.5
apple/safari < 15.6
Published Sep 20, 2022
Tracked Since Feb 18, 2026