Vulnerability Description
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. Processing maliciously crafted web content may lead to arbitrary code execution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Safari | < 16.0 |
| Apple | Ipados | < 15.7 |
| Apple | Iphone Os | < 15.7 |
| Fedoraproject | Fedora | 35 |
| Debian | Debian Linux | 10.0 |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/39
- http://seclists.org/fulldisclosure/2022/Oct/41Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/09/msg00034.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.gentoo.org/glsa/202305-32
- https://support.apple.com/en-us/HT213442Release NotesVendor Advisory
- https://support.apple.com/en-us/HT213445Release NotesVendor Advisory
- https://support.apple.com/en-us/HT213446Release NotesVendor Advisory
- https://www.debian.org/security/2022/dsa-5240Mailing ListThird Party Advisory
- https://www.debian.org/security/2022/dsa-5241Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/39
FAQ
What is CVE-2022-32886?
CVE-2022-32886 is a vulnerability with a CVSS score of 8.8 (HIGH). A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. Processing maliciously crafted web content may lead to arbitrar...
How severe is CVE-2022-32886?
CVE-2022-32886 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-32886?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Safari, Apple Ipados, Apple Iphone Os, Fedoraproject Fedora, Debian Debian Linux.