CVE-2022-32207: Apple macOS
Critical severity, CVSS 9.8. EPSS: 7.7% chance of exploitation in the next 30 days.
When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.
Affected products
- Apple macOS: before 13.0 (fixed in 13.0)
- Debian Debian Linux: version 11.0 only
- Fedoraproject Fedora: version 35 only
- Haxx Curl: from 7.69.0, before 7.84.0 (fixed in 7.84.0)
- Netapp Bootstrap OS: affected versions not specified
- Netapp Clustered Data Ontap: affected versions not specified
- Netapp Element Software: affected versions not specified
- Netapp h300s Firmware: affected versions not specified
- Netapp h410s Firmware: affected versions not specified
- Netapp h500s Firmware: affected versions not specified
- Netapp h700s Firmware: affected versions not specified
- Netapp Hci Management Node: affected versions not specified
- Netapp Solidfire: affected versions not specified
- Splunk Universal Forwarder: from 8.2.0, before 8.2.12 (fixed in 8.2.12); from 9.0.0, before 9.0.6 (fixed in 9.0.6); version 9.1.0 only
Published 2022-07-07. Last modified 2026-06-17.