CVE-2022-32853: Input Validation
AMD. A memory corruption issue was addressed with improved input validation.
Other sources
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing a maliciously crafted AppleScript binary may result in unexpected termination or disclosure of process memory.
— MITRE
APFS. The issue was addressed with improved memory handling.
— Apple
Apple Neural Engine. An integer overflow was addressed with improved input validation.
— Apple
Apple Neural Engine. An out-of-bounds read was addressed with improved bounds checking.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2022-32832
- CVE-2022-32826
- CVE-2022-32797
- CVE-2022-32853
- CVE-2022-32851
- CVE-2022-32831
- CVE-2022-32910
- CVE-2022-32825
- CVE-2022-32820
- CVE-2022-32805
- CVE-2022-32849
- CVE-2022-32839
- CVE-2022-32781
- CVE-2022-32819
- CVE-2022-32787
- CVE-2022-32785
- CVE-2022-32812
- CVE-2022-32811
- CVE-2022-32815
- CVE-2022-32813
- CVE-2021-30946
- CVE-2022-32823
- CVE-2022-32814
- CVE-2022-32786
- CVE-2022-32800
- CVE-2022-32838
- CVE-2022-32843
- CVE-2022-32857
- CVE-2022-32807
- CVE-2022-26704
- CVE-2022-32834
- CVE-2022-0156
- CVE-2022-0158
- CVE-2022-32860
- CVE-2022-32847
- CVE-2022-32848
- CVE-2022-32842
- CVE-2022-32799
- CVE-2021-4136
- CVE-2021-4166
- CVE-2021-4173
- CVE-2021-4187
- CVE-2021-4192
- CVE-2021-4193
- CVE-2021-46059
- CVE-2022-0128
- CVE-2022-32837
- CVE-2022-42858
- CVE-2022-32788
- CVE-2022-32880
- CVE-2022-42805
- CVE-2022-32948
- CVE-2022-32810
- CVE-2022-32840
- CVE-2022-32845
- CVE-2022-48578
- CVE-2022-32852
- CVE-2022-32789
- CVE-2022-32828
- CVE-2022-32793
- CVE-2022-32821
- CVE-2022-32897
- CVE-2022-32802
- CVE-2022-32841
- CVE-2022-48503
- CVE-2022-32817
- CVE-2022-32829
- CVE-2022-26981
- CVE-2022-46708
- CVE-2022-32796
- CVE-2022-32798
- CVE-2022-32818
- CVE-2022-32801
- CVE-2021-28544
- CVE-2022-24070
- CVE-2022-29046
- CVE-2022-29048
- CVE-2022-32933
- CVE-2022-32885
- CVE-2022-32861
- CVE-2022-32863
- CVE-2022-32816
- CVE-2022-32792
- CVE-2022-2294
Frequently Asked Questions
What is CVE-2022-32853?
CVE-2022-32853 is a vulnerability in AppleScript that allows for an out-of-bounds read issue due to improved input validation.
How does CVE-2022-32853 impact Apple users?
CVE-2022-32853 affects Apple users by potentially allowing an attacker to read sensitive information or cause a denial of service.
Which versions of Apple products are affected by CVE-2022-32853?
CVE-2022-32853 affects Apple products running macOS Catalina, macOS Big Sur (up to version 11.6.8), and macOS Monterey (up to version 12.5).
Is there a fix available for CVE-2022-32853?
Yes, Apple has addressed the CVE-2022-32853 vulnerability with improved input validation in macOS Catalina version 11.6.8, macOS Big Sur version 11.6.8, and macOS Monterey version 12.5.
Where can I find more information about CVE-2022-32853?
You can find more information about CVE-2022-32853 on Apple's official support page: [link](https://support.apple.com/en-us/HT213345).