CVE-2022-32905: Apple macOS

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13. Processing a maliciously crafted DMG file may lead to arbitrary code execution with system privileges.

Affected products

  • Apple macOS: before 13.0 (fixed in 13.0)

Published 2022-11-01. Last modified 2026-06-17.