VulnerabilityModified
CVE-2022-32833
An unauthorized user may be able to access browsing history.
MEDIUM 5.3EPSS 0.62%
Does this matter?
Lower severity and a low EPSS score (0.62%). Track it; it rarely justifies an emergency change on its own.
Description
An issue existed with the file paths used to store website data. The issue was resolved by improving how website data is stored. This issue is fixed in iOS 16. An unauthorized user may be able to access browsing history.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.62% probability · 48th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-922
- Affected
- apple/safari · apple/iphone os · apple/macos
- Source
- product-security@apple.com
References
- https://support.apple.com/en-us/HT213446Release Notes, Vendor Advisory
- https://support.apple.com/kb/HT213442Release Notes, Vendor Advisory
- https://support.apple.com/kb/HT213488Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT213446Release Notes, Vendor Advisory
- https://support.apple.com/kb/HT213442Release Notes, Vendor Advisory
- https://support.apple.com/kb/HT213488Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.