CVE-2022-32883

MEDIUM

Apple Ipados < 15.7 - Improper Access Control

Title source: rule
STIX 2.1

Description

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to read sensitive location information.

Exploits (1)

nomisec WORKING POC 18 stars
by breakpointHQ · poc
https://github.com/breakpointHQ/CVE-2022-32883

References (13)

Core 13
Core References
Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2022/Oct/41
Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2022/Oct/28
Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2022/Oct/39
Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2022/Oct/40
Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2022/Oct/49
Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2022/Oct/43
Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2022/Oct/45
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213443
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213444
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213445
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213446
Release Notes, Vendor Advisory
https://support.apple.com/kb/HT213488

Scores

CVSS v3 5.5
EPSS 0.0013
EPSS Percentile 31.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (4)
apple/ipados < 15.7
apple/iphone_os < 16.0
apple/macos 11.0 - 11.7
apple/watchos < 9.0
Published Sep 20, 2022
Tracked Since Feb 18, 2026