Executive brief
An out-of-bounds write vulnerability in multiple Apple operating systems allows an application to execute arbitrary code with kernel privileges due to insufficient bounds checking. This vulnerability has been reported as being actively exploited in the wild.
Affected products
- Apple macOS Monterey 12.0.0 to 12.3.1
- Apple macOS Big Sur 11.0 to 11.6.6
- Apple iOS and iPadOS up to 15.4.1
- Apple tvOS up to 15.5
- Apple watchOS up to 8.6
Timeline
- 2022-04-04: disclosed: Vulnerability added to CISA KEV catalog
- 2022-04-04: kev added
- 2022-05-26: advisory: NVD published date
- 2022-05-14: patched: Apple released security updates for various OS versions
- 2022-04-04: exploited: Apple is aware of reports of active exploitation