CVE-2022-22625: Input Validation
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. Processing a maliciously crafted AppleScript binary may result in unexpected application termination or disclosure of process memory.
Other sources
AppleScript. An out-of-bounds read was addressed with improved input validation.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2022-22633
- CVE-2022-22665
- CVE-2022-22631
- CVE-2022-22648
- CVE-2022-22627
- CVE-2022-22626
- CVE-2022-22625
- CVE-2022-22597
- CVE-2022-22616
- CVE-2022-26691
- CVE-2022-46706
- CVE-2022-22661
- CVE-2022-22613
- CVE-2022-22615
- CVE-2022-22614
- CVE-2022-22638
- CVE-2022-22632
- CVE-2022-22647
- CVE-2022-22656
- CVE-2022-22672
- CVE-2022-22617
- CVE-2022-26688
- CVE-2022-22650
- CVE-2022-22599
- CVE-2022-22651
- CVE-2022-22662
- CVE-2022-22582
- CVE-2022-22589
- CVE-2022-22669
- CVE-2022-22630
- CVE-2022-22663
- CVE-2021-22946
- CVE-2021-22947
- CVE-2021-22945
- CVE-2022-22643
- CVE-2022-22657
- CVE-2022-22664
- CVE-2021-30977
- CVE-2022-22611
- CVE-2022-22612
- CVE-2022-22641
- CVE-2022-22640
- CVE-2021-30946
- CVE-2021-36976
- CVE-2022-21658
- CVE-2022-22644
- CVE-2022-26690
- CVE-2022-22609
- CVE-2022-22655
- CVE-2022-22600
- CVE-2022-22639
- CVE-2022-22660
- CVE-2022-22621
- CVE-2021-4136
- CVE-2021-4166
- CVE-2021-4173
- CVE-2021-4187
- CVE-2021-4192
- CVE-2021-4193
- CVE-2021-46059
- CVE-2022-0128
- CVE-2022-0156
- CVE-2022-0158
- CVE-2021-30918
- CVE-2022-22610
- CVE-2022-22624
- CVE-2022-22628
- CVE-2022-22629
- CVE-2022-22637
- CVE-2022-22668
Frequently Asked Questions
What is CVE-2022-22625?
CVE-2022-22625 is a vulnerability in AppleScript that allowed an out-of-bounds read, but has been fixed with improved input validation.
What software versions are affected by CVE-2022-22625?
CVE-2022-22625 affects Apple Catalina, macOS Big Sur (up to 11.6.5), and macOS Monterey (up to 12.3).
How can I fix CVE-2022-22625?
To fix CVE-2022-22625, update your operating system to the latest version available for your software version.
Are there any references for CVE-2022-22625?
Yes, you can refer to the following links for more information: [Support Link 1](https://support.apple.com/en-us/HT213184), [Support Link 2](https://support.apple.com/en-us/HT213183), [Support Link 3](https://support.apple.com/en-us/HT213185).
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-22625?
The CWE ID for CVE-2022-22625 is 20.