
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-32797 is a security vulnerability discovered in Apple's AppleScript component affecting macOS systems (Monterey, Big Sur, and Catalina). The vulnerability was disclosed and patched in July 2022 as part of Apple's security updates. It was discovered by Mickey Jin (@patch1t) and Ye Zhang (@co0py_Cat) of Baidu Security (Apple Support).
The vulnerability is an out-of-bounds read issue in the AppleScript framework that occurs when processing maliciously crafted AppleScript binary files. The specific flaw exists within the AppleScript framework where crafted data in an SCPT file can trigger a read past the end of an allocated data structure. The issue was addressed by Apple through improved checks in their security updates (ZDI). The vulnerability has been assigned a CVSS score of 3.3 (AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N).
When exploited, this vulnerability could result in unexpected termination of applications or disclosure of process memory. An attacker could leverage this vulnerability in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process (ZDI).
Apple has addressed this vulnerability by implementing improved checks in their security updates. Users should update to macOS Monterey 12.5, macOS Big Sur 11.6.8, or Security Update 2022-005 Catalina, depending on their operating system version (Apple Support).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."