CVE-2022-32883

MEDIUM

iPadOS < 15.7 - Unauthorized Sensitive Location Information Access

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-32883. PoCs published by breakpointHQ.

AI-analyzed exploit summary This repository contains functional exploit code for CVE-2022-32883, which leverages Apple Maps to determine the physical location of a device by analyzing distance data. The PoC includes scripts to interact with the Maps app and perform geolocation triangulation.

Description

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to read sensitive location information.

Exploits (1)

nomisec WORKING POC 18 stars
by breakpointHQ · poc
https://github.com/breakpointHQ/CVE-2022-32883

This repository contains functional exploit code for CVE-2022-32883, which leverages Apple Maps to determine the physical location of a device by analyzing distance data. The PoC includes scripts to interact with the Maps app and perform geolocation triangulation.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Apple Maps (macOS)
No auth needed
Prerequisites: Apple Maps installed on macOS · Device location services enabled
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (13)

Core 13
Core References
Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2022/Oct/41
Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2022/Oct/28
Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2022/Oct/39
Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2022/Oct/40
Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2022/Oct/49
Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2022/Oct/43
Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2022/Oct/45
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213443
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213444
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213445
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213446
Release Notes, Vendor Advisory
https://support.apple.com/kb/HT213488

Scores

CVSS v3 5.5
EPSS 0.0047
EPSS Percentile 37.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (4)
apple/ipados < 15.7
apple/iphone_os < 16.0
apple/macos 11.0 - 11.7
apple/watchos < 9.0
Published Sep 20, 2022
Tracked Since Feb 18, 2026