Lucene search

K
nvd[email protected]NVD:CVE-2022-32913
HistoryNov 01, 2022 - 8:15 p.m.

CVE-2022-32913

2022-11-0120:15:19
web.nvd.nist.gov
2
privacy
observability
app states
macos big sur 11.7
macos ventura 13
ios 16
watchos 9
macos monterey 12.6
tvos 16
sandbox
camera

3.3 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

0.0005 Low

EPSS

Percentile

17.9%

The issue was addressed with additional restrictions on the observability of app states. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, watchOS 9, macOS Monterey 12.6, tvOS 16. A sandboxed app may be able to determine which app is currently using the camera.

Affected configurations

NVD
Node
appleiphone_osRange<16.0
OR
applemacosRange11.011.7
OR
applemacosRange12.0.012.6
OR
appletvosRange<16.0
OR
applewatchosRange<9.0

3.3 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

0.0005 Low

EPSS

Percentile

17.9%

Related for NVD:CVE-2022-32913