CVE-2022-32907 is a privilege escalation vulnerability affecting Apple tvOS, iOS, and watchOS, where a malicious application could execute arbitrary code with kernel privileges. It carries a high CVSS score of 7.8, indicating a significant impact with high confidentiality, integrity, and availability risks, though it requires user interaction for exploitation. While no public exploits or active exploitation have been observed, and community discussion is minimal, Apple has addressed this issue with improved checks in tvOS 16, iOS 16, and watchOS 9.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 16.0CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 16.0CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | ||
< 9.0CPE matchmatch criteria | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.