CVE-2022-32905 is a high-severity vulnerability affecting macOS Ventura 13 and earlier versions, where processing a maliciously crafted DMG file can lead to arbitrary code execution with system privileges. The vulnerability, rated 7.8 CVSS, stems from insufficient validation of symlinks, allowing an attacker to leverage local access with user interaction to achieve full compromise. While no public exploits or Metasploit modules are available, and community discussion is minimal, the potential for high impact on confidentiality, integrity, and availability remains significant. Apple has addressed this issue with improved symlink validation in macOS Ventura 13.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 13CPE match | cpe:2.3:a:apple:macos:*:*:*:*:*:*:*:* | ||
< 13.0CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.