Junglewise Threat Intelligence

CVE-2022-22674: Apple macOS Out-of-Bounds Read Vulnerability

CVE-2022-22674 · Severity: critical · CVSS 5.5 · Exploited in the wild · Published 2022-04-04

Technologies: Apple macOS Monterey, Apple macOS. Vendors: Apple.

Executive brief

An out-of-bounds read vulnerability in macOS kernel memory allows a local application to disclose sensitive kernel information. The issue was caused by insufficient input validation and has been addressed in macOS Monterey 12.3.1, Big Sur 11.6.6, and Catalina Security Update 2022-004.

Affected products

  • Apple macOS Monterey < 12.3.1
  • Apple macOS Big Sur < 11.6.6
  • Apple macOS Catalina Security Update 2022-004

Timeline

  • 2022-04-04: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-04-04: disclosed
  • 2022-05-26: advisory: NVD Published Date
  • 2022-04-04: exploited: Reported as exploited in the wild per CISA KEV and advisory.

Related threats