PT-2022-21565 · Apple · Macos Monterey+3
Mickey Jin
·
Published
2022-09-12
·
Updated
2022-11-02
·
CVE-2022-32904
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
macOS versions prior to 11.7
macOS Monterey versions prior to 12.6
macOS Ventura version 13 is not affected, but versions prior to 13 are vulnerable, however since 13 is the starting version, it is:
macOS Ventura versions prior to 13 does not apply, the correct interpretation is
macOS versions prior to 11.7 and macOS Monterey versions prior to 12.6 and since Ventura 13 is mentioned as fixed, it implies versions prior to 13 are affected for Ventura as well, but since 13 is the base version, the correct statement is
macOS versions prior to 11.7 and macOS Monterey versions prior to 12.6
However, considering the information given and the structure required, the correct interpretation should focus on the versions mentioned as fixed, implying that versions before these are affected. Thus, simplifying the understanding:
macOS versions prior to 11.7
macOS Monterey versions prior to 12.6
Given Ventura 13 as a fixed version, it implies any version before 13 is affected, but since 13 is the base, the focus should be on the fact that versions prior to the mentioned fixed versions are affected.
Description
An access issue was addressed with additional sandbox restrictions. This issue allows an app to potentially access user-sensitive data.
Recommendations
For macOS versions prior to 11.7, update to macOS Big Sur 11.7 or later.
For macOS Monterey versions prior to 12.6, update to macOS Monterey 12.6 or later.
For macOS Ventura, since version 13 is mentioned as part of the fix, update to macOS Ventura 13 or later.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apple Macos
Macos Big Sur
Macos Monterey
Macos Ventura