ZeroHour

CVE-2022-22587

KEVmass

Memory Corruption in Apple iOS, iPadOS, and macOS Allows Kernel-Privilege Code Execution

CISA: Apple Memory Corruption Vulnerability

CVSS 3.1
9.8 critical
EPSS
12%p96
Published
()
KEV added
AI analysis

CVE-2022-22587 is a memory corruption flaw (CWE-787, out-of-bounds write) in Apple's operating systems that Apple addressed with improved input validation. It is triggered by a malicious application already running on a vulnerable device, which can exploit the corruption to execute arbitrary code with kernel privileges — the highest privilege level of the OS. All iPhones and iPads running iOS/iPadOS versions earlier than 15.3 and Macs running macOS Monterey earlier than 12.2 or Big Sur earlier than 11.6.3 are affected. Apple reported the issue as actively exploited, and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-01-28; EPSS rates it at 11.6% probability of exploitation in the next 30 days (96th percentile). It was one of two actively exploited Apple zero-days patched in Apple's January 2022 emergency updates.

What to do: Update iPhones and iPads to iOS/iPadOS 15.3 and Macs to macOS Monterey 12.2 or Big Sur 11.6.3 (or later). Inventory managed fleets for devices below these versions, since the flaw is exploited in the wild and CISA KEV requires applying vendor updates. Until devices are patched, limit exposure by avoiding installation of untrusted applications on vulnerable iPhones, iPads, and Macs.

Affected
Apple iPhone OS (iOS)iOS versions earlier than 15.3 (fixed in iOS 15.3)
Apple iPadOSiPadOS versions earlier than 15.3 (fixed in iPadOS 15.3)
Apple macOS MontereymacOS Monterey versions earlier than 12.2 (fixed in 12.2)
Apple macOS Big SurmacOS Big Sur versions earlier than 11.6.3 (fixed in 11.6.3)
Estimated exposure
mass>1 billion active Apple devices (all iPhones, iPads, and Macs below the fixed versions) — Apple's active device installed base was publicly reported at roughly 1.8 billion devices in early 2022, and essentially every iPhone, iPad, and Mac not yet updated to iOS/iPadOS 15.3, macOS Monterey 12.2, or Big Sur 11.6.3 is plausibly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, macOS Big Sur 11.6.3, macOS Monterey 12.2. A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..

CISA Known Exploited Vulnerability
Affected
Apple iOS and macOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
ipados, iphone os, macos
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news