CVE-2022-32893

HIGH(8.8)KEV

Apple iOS and macOS Out-of-Bounds Write Vulnerability

Description

CVE-2022-32893 is an out-of-bounds write vulnerability in Apple iOS and macOS WebKit that allows remote code execution when processing maliciously crafted web content. The flaw in WebKit, the browser engine powering Safari and all iOS browsers, enables an attacker to execute arbitrary code by luring a victim to a specially crafted webpage. CISA has added CVE-2022-32893 to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. With an EPSS score of 0.23% (45th percentile), exploitation appears to be targeted, but the remote attack vector through web browsing makes this vulnerability particularly dangerous for all Apple device users.

KEV Information

Vendor
Apple
Product
iOS and macOS
Date Added
August 18, 2022
Due Date
September 8, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
applesafari< 15.6.1
appleipados< 15.6.1
appleiphone os< 15.6.1
applemacos>= 12.0, < 12.5.1
fedoraprojectfedora35; 36
debiandebian linux10.0; 11.0
webkitgtkwebkitgtk< 2.36.7
wpewebkitwpe webkit< 2.36.7

Multiple CVSS Assessments

Source: [email protected](Primary)
8.8
HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
8.8
HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-787: Out-of-bounds Write

CVE-2022-32893 exploits an out-of-bounds write vulnerability in Apple's WebKit rendering engine, where processing maliciously crafted web content triggers a write operation beyond the boundaries of an allocated memory buffer. In the context of WebKit, this memory corruption can be leveraged to overwrite critical data structures in the browser's memory space, enabling the attacker to achieve remote code execution simply by having the victim visit a malicious webpage.

Learn more: CWE-787 — Out-of-bounds Write

Impact Analysis

CVE-2022-32893 is a remotely exploitable vulnerability that requires no authentication and only user interaction in the form of visiting a malicious webpage. The out-of-bounds write in WebKit can lead to complete compromise of the browser process and potentially the underlying operating system when chained with kernel vulnerabilities such as CVE-2022-32894. Confidentiality, integrity, and availability are all at high risk, as successful exploitation grants the attacker code execution within the context of the browser process, which can access browsing data, credentials, and other sensitive information. The remote attack vector via network-delivered web content makes this vulnerability especially concerning, as exploitation can occur through phishing emails, malicious advertisements, or compromised websites without any prior access to the victim's device.

Exploit Maturity

CISA has confirmed active exploitation of CVE-2022-32893 in the wild by adding it to the Known Exploited Vulnerabilities catalog on August 18, 2022, with a remediation deadline of September 8, 2022. The vulnerability was reportedly used in targeted attacks, likely as part of exploit chains combining the WebKit remote code execution with the kernel privilege escalation CVE-2022-32894 to achieve full device compromise. No publicly tagged proof-of-concept exploit code is listed in the available references, but the confirmed in-the-wild activity indicates operational exploits exist. With an EPSS score of approximately 0.23% (45th percentile), exploitation is not currently widespread but remains a significant threat for targeted attacks.

Remediation

  1. Apply Apple security updates immediately: Install the patches referenced in Apple security advisories HT213412 and HT213413, which address the WebKit out-of-bounds write vulnerability.
  2. Update all Apple devices and browsers: Since WebKit is the mandatory rendering engine for all iOS browsers, updating iOS itself is the only way to patch this vulnerability on iPhones and iPads. On macOS, update Safari and the operating system.
  3. Implement web filtering controls: Deploy network-level web filtering to block access to known malicious domains and reduce the attack surface for web-based exploit delivery.
  4. Enable Lockdown Mode on high-risk devices: For users at elevated risk of targeted attacks, Apple's Lockdown Mode significantly reduces the WebKit attack surface by disabling certain web technologies.
  5. Educate users about phishing risks: Since exploitation requires visiting a malicious webpage, security awareness training about suspicious links in emails and messages provides an additional layer of defense.

Technical Details

CVE-2022-32893 is rooted in an out-of-bounds write vulnerability within Apple's WebKit rendering engine, which powers Safari and all web browsing on iOS devices. The vulnerability is triggered when WebKit processes specially crafted web content that causes the engine to write data beyond the boundaries of an allocated memory buffer during rendering operations. An attacker can craft a malicious HTML page that exploits this memory corruption to overwrite adjacent objects in the WebKit heap, ultimately gaining control of program execution flow. The remote exploitation via crafted web content means no authentication or prior device access is required — the victim only needs to navigate to the attacker's webpage. This vulnerability was observed being chained with CVE-2022-32894, a kernel out-of-bounds write, creating a complete exploit chain from remote web access to kernel-level code execution on the victim's device.

Frequently Asked Questions

Is CVE-2022-32893 being actively exploited?

Yes. CISA has confirmed active exploitation of CVE-2022-32893 by adding it to the Known Exploited Vulnerabilities catalog. Apple has acknowledged reports of this vulnerability being exploited in targeted attacks, likely chained with CVE-2022-32894 for full device compromise. Immediate patching is strongly recommended.

What products are affected by CVE-2022-32893?

CVE-2022-32893 affects Apple iOS and macOS through the WebKit rendering engine. This impacts Safari and all web browsers on iOS, since Apple requires all iOS browsers to use WebKit. iPhones, iPads, and Macs running unpatched software versions are vulnerable.

How do I fix CVE-2022-32893?

Apply the security updates from Apple referenced in advisories HT213412 and HT213413. On iOS, update the operating system to the latest available version, which will patch WebKit for all browsers. On macOS, update both Safari and the operating system.

How severe is CVE-2022-32893?

CVE-2022-32893 is a high-severity remote code execution vulnerability that can be exploited simply by having a user visit a malicious webpage. The combination of remote exploitability, no authentication requirement, and confirmed in-the-wild exploitation makes this a critical patching priority. The EPSS score of 0.23% (45th percentile) indicates targeted rather than mass exploitation.

CVSS Score

8.8
HIGH(8.8)

EPSS Score

EPSS Score9.86%
EPSS Percentile95.2%

Dates

PublishedAugust 24, 2022
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.