CVE-2022-48503 is a critical vulnerability affecting Apple's JavaScriptCore across iOS, iPadOS, macOS, tvOS, watchOS, and Safari. This flaw, stemming from insufficient bounds checks, allows for arbitrary code execution when processing specially crafted web content. With a CVSS score of 8.8 (HIGH), it presents a significant risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. Notably, this vulnerability is actively exploited in the wild, as confirmed by its presence on CISA's KEV catalog, and has garnered substantial community discussion and media coverage despite a lack of public exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 15.6CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
< 15.6CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 15.6CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
>= 12.0.0, < 12.5CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
< 15.6CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.