CVE-2022-32851: Input Validation
AMD. A memory corruption issue was addressed with improved input validation.
Other sources
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing a maliciously crafted AppleScript binary may result in unexpected termination or disclosure of process memory.
— MITRE
APFS. The issue was addressed with improved memory handling.
— Apple
Apple Neural Engine. An integer overflow was addressed with improved input validation.
— Apple
Apple Neural Engine. An out-of-bounds read was addressed with improved bounds checking.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2022-32832
- CVE-2022-32826
- CVE-2022-32797
- CVE-2022-32853
- CVE-2022-32851
- CVE-2022-32831
- CVE-2022-32910
- CVE-2022-32825
- CVE-2022-32820
- CVE-2022-32805
- CVE-2022-32849
- CVE-2022-32839
- CVE-2022-32781
- CVE-2022-32819
- CVE-2022-32787
- CVE-2022-32785
- CVE-2022-32812
- CVE-2022-32811
- CVE-2022-32815
- CVE-2022-32813
- CVE-2021-30946
- CVE-2022-32823
- CVE-2022-32814
- CVE-2022-32786
- CVE-2022-32800
- CVE-2022-32838
- CVE-2022-32843
- CVE-2022-32857
- CVE-2022-32807
- CVE-2022-26704
- CVE-2022-32834
- CVE-2022-0156
- CVE-2022-0158
- CVE-2022-32860
- CVE-2022-32847
- CVE-2022-32848
- CVE-2022-32842
- CVE-2022-32799
- CVE-2021-4136
- CVE-2021-4166
- CVE-2021-4173
- CVE-2021-4187
- CVE-2021-4192
- CVE-2021-4193
- CVE-2021-46059
- CVE-2022-0128
- CVE-2022-32837
- CVE-2022-42858
- CVE-2022-32788
- CVE-2022-32880
- CVE-2022-42805
- CVE-2022-32948
- CVE-2022-32810
- CVE-2022-32840
- CVE-2022-32845
- CVE-2022-48578
- CVE-2022-32852
- CVE-2022-32789
- CVE-2022-32828
- CVE-2022-32793
- CVE-2022-32821
- CVE-2022-32897
- CVE-2022-32802
- CVE-2022-32841
- CVE-2022-48503
- CVE-2022-32817
- CVE-2022-32829
- CVE-2022-26981
- CVE-2022-46708
- CVE-2022-32796
- CVE-2022-32798
- CVE-2022-32818
- CVE-2022-32801
- CVE-2021-28544
- CVE-2022-24070
- CVE-2022-29046
- CVE-2022-29048
- CVE-2022-32933
- CVE-2022-32885
- CVE-2022-32861
- CVE-2022-32863
- CVE-2022-32816
- CVE-2022-32792
- CVE-2022-2294
Frequently Asked Questions
What is the vulnerability ID for this AppleScript issue?
The vulnerability ID for this AppleScript issue is CVE-2022-32851.
What is the description of this vulnerability?
This vulnerability is an out-of-bounds read issue in AppleScript that has been addressed with improved input validation.
Which software versions are affected by this vulnerability?
This vulnerability affects Apple macOS Catalina, macOS Big Sur (up until version 11.6.8), and macOS Monterey (up until version 12.5).
How can I fix this vulnerability?
To fix this vulnerability, update your macOS to the latest available version. Refer to the Apple support links provided for more information.
What is the Common Weakness Enumeration (CWE) ID for this vulnerability?
The Common Weakness Enumeration (CWE) ID for this vulnerability is CWE-20.