CVE-2022-32207: Apple macOS

Critical severity, CVSS 9.8. EPSS: 7.7% chance of exploitation in the next 30 days.

When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.

Affected products

  • Apple macOS: before 13.0 (fixed in 13.0)
  • Debian Debian Linux: version 11.0 only
  • Fedoraproject Fedora: version 35 only
  • Haxx Curl: from 7.69.0, before 7.84.0 (fixed in 7.84.0)
  • Netapp Bootstrap OS: affected versions not specified
  • Netapp Clustered Data Ontap: affected versions not specified
  • Netapp Element Software: affected versions not specified
  • Netapp h300s Firmware: affected versions not specified
  • Netapp h410s Firmware: affected versions not specified
  • Netapp h500s Firmware: affected versions not specified
  • Netapp h700s Firmware: affected versions not specified
  • Netapp Hci Management Node: affected versions not specified
  • Netapp Solidfire: affected versions not specified
  • Splunk Universal Forwarder: from 8.2.0, before 8.2.12 (fixed in 8.2.12); from 9.0.0, before 9.0.6 (fixed in 9.0.6); version 9.1.0 only

Published 2022-07-07. Last modified 2026-06-17.