CVE-2022-48503: Apple Multiple Products Unspecified Vulnerability
AMD. A memory corruption issue was addressed with improved input validation.
Other sources
APFS. The issue was addressed with improved memory handling.
— Apple
Apple macOS, iOS, tvOS, Safari, and watchOS contain an unspecified vulnerability in JavaScriptCore that when processing web content may lead to arbitrary code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
— CISA
Apple Neural Engine. An integer overflow was addressed with improved input validation.
— Apple
Apple Neural Engine. An out-of-bounds read was addressed with improved bounds checking.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 15.6 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 8.7 - Upgrade
Upgrade
macOSto a version that resolves this vulnerability.Fixed in 12.5 - Upgrade
Upgrade
Safarito a version that resolves this vulnerability.Fixed in 15.6 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 15.6 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 15.6 - Upgrade
Upgrade
Apple iOSto a version that resolves this vulnerability.Fixed in 15.6 - Upgrade
Upgrade
Apple iPadOSto a version that resolves this vulnerability.Fixed in 15.6 - Upgrade
Upgrade
watchOSto a version that resolves this vulnerability.Fixed in 8.7 - Upgrade
Upgrade
macOS Montereyto a version that resolves this vulnerability.Fixed in 12.5 - Configuration
Enable the hardened runtime for the affected Apple component(s); the vendor notes the issue was addressed by enabling hardened runtime.
Apple software (unspecified) hardened runtime = enabled - Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
- Compensating control
Discontinue use of the product if mitigations are unavailable (users should discontinue product utilization).
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2022-32832
- CVE-2022-32788
- CVE-2022-32824
- CVE-2022-32826
- CVE-2022-32820
- CVE-2022-32825
- CVE-2022-32828
- CVE-2022-32839
- CVE-2022-32819
- CVE-2022-32793
- CVE-2022-32821
- CVE-2022-32849
- CVE-2022-32787
- CVE-2022-32841
- CVE-2022-32802
- CVE-2022-32830
- CVE-2022-48503
- CVE-2022-32813
- CVE-2022-32815
- CVE-2022-32817
- CVE-2022-32844
- CVE-2022-26981
- CVE-2022-32823
- CVE-2022-32814
- CVE-2022-32857
- CVE-2022-32863
- CVE-2022-32816
- CVE-2022-32792
- CVE-2022-32837
- CVE-2022-32847
- CVE-2022-32845
- CVE-2022-32840
- CVE-2022-32810
- CVE-2022-42858
- CVE-2022-32880
- CVE-2022-42805
- CVE-2022-32948
- CVE-2022-48578
- CVE-2022-32797
- CVE-2022-32851
- CVE-2022-32852
- CVE-2022-32853
- CVE-2022-32831
- CVE-2022-32910
- CVE-2022-32789
- CVE-2022-32805
- CVE-2022-32897
- CVE-2022-32785
- CVE-2022-32811
- CVE-2022-32812
- CVE-2022-32829
- CVE-2022-32786
- CVE-2022-32800
- CVE-2022-32838
- CVE-2022-32843
- CVE-2022-46708
- CVE-2022-32796
- CVE-2022-32842
- CVE-2022-32798
- CVE-2022-32799
- CVE-2022-32818
- CVE-2022-32807
- CVE-2022-32801
- CVE-2021-28544
- CVE-2022-24070
- CVE-2022-29046
- CVE-2022-29048
- CVE-2022-32834
- CVE-2022-32933
- CVE-2022-32885
- CVE-2022-32861
- CVE-2022-2294
- CVE-2022-32860
- CVE-2022-32848
- CVE-2022-32784
- CVE-2022-32855
- CVE-2022-26768
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-48503.
What is the severity of CVE-2022-48503?
The severity of CVE-2022-48503 is high with a CVSS score of 8.8.
Which software versions are affected by CVE-2022-48503?
CVE-2022-48503 affects macOS Monterey 12.5, Safari 15.6, iPadOS 15.6, iOS 15.6, tvOS 15.6, and watchOS 8.7.
How was CVE-2022-48503 addressed?
CVE-2022-48503 was addressed with improved bounds checks in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, and Safari 15.6.
What is the potential impact of CVE-2022-48503?
CVE-2022-48503 may allow arbitrary code execution when processing web content.