PT-2022-21566 · Apple · Apple Macos

Ron Masas

·

Published

2022-10-24

·

Updated

2024-01-30

·

CVE-2022-32905

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions macOS versions prior to 13
Description The issue concerns the processing of maliciously crafted DMG files, which may lead to arbitrary code execution with system privileges. This was addressed with improved validation of symlinks.
Recommendations For versions prior to macOS 13, update to macOS Ventura 13 to resolve the issue.

Fix

Link Following

Weakness Enumeration

Related Identifiers

CVE-2022-32905

Affected Products

Apple Macos