Lucene search

K
cveAppleCVE-2022-32945
HistoryDec 15, 2022 - 7:15 p.m.

CVE-2022-32945

2022-12-1519:15:18
apple
web.nvd.nist.gov
66
cve-2022-32945
access issue
sandbox restrictions
third-party apps
macos ventura 13
recording audio
airpods

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

AI Score

5.5

Confidence

Low

EPSS

0.001

Percentile

31.8%

An access issue was addressed with additional sandbox restrictions on third-party apps. This issue is fixed in macOS Ventura 13. An app may be able to record audio with paired AirPods.

Affected configurations

Nvd
Vulners
Node
appleipadosRange<16.0
OR
appleiphone_osRange<16.1
OR
applemacosRange<13.0
VendorProductVersionCPE
appleipados*cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
appleiphone_os*cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
applemacos*cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Apple",
    "product": "macOS",
    "versions": [
      {
        "version": "unspecified",
        "lessThan": "13",
        "status": "affected",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

AI Score

5.5

Confidence

Low

EPSS

0.001

Percentile

31.8%

Related for CVE-2022-32945