CVE-2022-48503
Act now ● On CISA KEV — actively exploited
Actively exploited — on the CISA KEV list.
CVSS base
—
EPSS — probability of exploitation (30 days)
3.2%
87.6th percentile
CISA KEV
Listed
Added 2025-10-20 · patch by 2025-11-10
Weakness / dates
—
Published — · modified —
Timeline
- 2025-10-20 — Added to CISA KEV (actively exploited)
- 2025-11-10 — CISA patch-by deadline
Description
Apple macOS, iOS, tvOS, Safari, and watchOS contain an unspecified vulnerability in JavaScriptCore that when processing web content may lead to arbitrary code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.