Vulnerability Intelligence Report
Apple Multiple Products Unspecified Vulnerability
CVE-2022-48503
The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing web content may lead to arbitrary code execution.
CISA KEV
SSVC: Active Exploitation
CVSS Base Score
8.8
HIGH
Exploitability:2.9
Impact Score:5.9
EPSS Probability:3.12%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-129 ↗CWE-129 Improper Validation of Array Index
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Apple | macOS | unspecified < 12.5 (affected) |
| Apple | tvOS | unspecified < 15.6 (affected) |
| Apple | Safari | unspecified < 15.6 (affected) |
| Apple | watchOS | unspecified < 8.7 (affected) |
| Apple | iOS and iPadOS | unspecified < 15.6 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Apple Inc. · Vendor · USA |
| Reserved | 2023-06-12T20:53:52 |
| Published | 2023-08-14T22:40:49 |
| Last Updated | 2025-10-21T23:05:41 |
Community Chatter & Buzz