Junglewise Threat Intelligence

CVE-2022-22587: Apple Memory Corruption Vulnerability

CVE-2022-22587 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-01-28

Technologies: Cisco IOS, Apple macOS, Apple iPadOS, Apple macOS Monterey. Vendors: Cisco, Apple.

Executive brief

A memory corruption vulnerability in the Apple IOMobileFrameBuffer component allows a malicious application to execute arbitrary code with kernel privileges. The issue stems from insufficient input validation and has been reported as being actively exploited in the wild.

Affected products

  • Apple iOS before 15.3
  • Apple iPadOS before 15.3
  • Apple macOS Big Sur before 11.6.3
  • Apple macOS Monterey before 12.2

Timeline

  • 2022-01-28: disclosed: Initial publication date
  • 2022-01-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-01-28: patched: Fixed in iOS 15.3, iPadOS 15.3, macOS Big Sur 11.6.3, and macOS Monterey 12.2
  • 2022-01-28: exploited: Apple reported awareness of active exploitation at time of disclosure.

Related threats