First published: Wed Jul 20 2022(Updated: )
AppleScript. An out-of-bounds read issue was addressed with improved input validation.
Credit: Ye Zhang @co0py_Cat Baidu SecurityYe Zhang @co0py_Cat Baidu SecurityYe Zhang @co0py_Cat Baidu SecurityYe Zhang @co0py_Cat Baidu SecurityYe Zhang @co0py_Cat Baidu SecurityYe Zhang @co0py_Cat Baidu SecurityYe Zhang @co0py_Cat Baidu Security product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Catalina | ||
Apple macOS Big Sur | <11.6.8 | 11.6.8 |
Apple Mac OS X | =10.15.7-security_update_2020-001 | |
Apple Mac OS X | =10.15.7-security_update_2021-001 | |
Apple Mac OS X | =10.15.7-security_update_2021-002 | |
Apple Mac OS X | =10.15.7-security_update_2021-003 | |
Apple Mac OS X | =10.15.7-security_update_2021-004 | |
Apple Mac OS X | =10.15.7-security_update_2021-005 | |
Apple Mac OS X | =10.15.7-security_update_2021-006 | |
Apple Mac OS X | =10.15.7-security_update_2021-007 | |
Apple Mac OS X | =10.15.7-security_update_2021-008 | |
Apple Mac OS X | =10.15.7-security_update_2022-001 | |
Apple Mac OS X | =10.15.7-security_update_2022-002 | |
Apple Mac OS X | =10.15.7-security_update_2022-003 | |
Apple macOS | <10.15.7 | |
Apple macOS | >=11.0<11.6.8 | |
Apple macOS | >=12.0<12.5 | |
Apple macOS | =10.15.7 | |
Apple macOS | =10.15.7-security_update_2022-004 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this AppleScript issue is CVE-2022-32851.
This vulnerability is an out-of-bounds read issue in AppleScript that has been addressed with improved input validation.
This vulnerability affects Apple macOS Catalina, macOS Big Sur (up until version 11.6.8), and macOS Monterey (up until version 12.5).
To fix this vulnerability, update your macOS to the latest available version. Refer to the Apple support links provided for more information.
The Common Weakness Enumeration (CWE) ID for this vulnerability is CWE-20.