CVE-2022-48503
Apple macOS, Apple tvOS, Apple Safari
Published 14 Aug 2023 · updated 17 Jun 2026 · Analyzed
8.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 20 Oct 2025, with a remediation deadline of 10 Nov 2025 for US federal agencies.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Description
The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing web content may lead to arbitrary code execution.
References
- support.apple.com/en-us/HT213340 · Release Notes, Vendor Advisory
- support.apple.com/en-us/HT213341 · Release Notes, Vendor Advisory
- support.apple.com/en-us/HT213342 · Release Notes, Vendor Advisory
- support.apple.com/en-us/HT213345 · Release Notes, Vendor Advisory
- support.apple.com/en-us/HT213346 · Release Notes, Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-48503 · US Government Resource