ZeroHour

CVE-2022-22674

KEVmass

Out-of-Bounds Read in Apple macOS Kernel Discloses Kernel Memory

CISA: Apple macOS Out-of-Bounds Read Vulnerability

CVSS 3.1
5.5 medium
EPSS
1%p65
Published
()
KEV added
AI analysis

Apple's macOS kernel contained an out-of-bounds read (CWE-125) caused by insufficient input validation, which allowed a local user to read kernel memory. It is triggered by a local application or user on the machine interacting with the vulnerable kernel code path; there is no remote or unauthenticated attack vector. Successful exploitation discloses kernel memory (high confidentiality impact per the CVSS 5.5 local-attack score), but it does not by itself provide code execution or privilege escalation. All users of macOS Monterey, Big Sur, and Catalina who have not applied the March 2022 fixes are affected. The flaw is confirmed exploited in the wild: Apple shipped emergency patches alongside a WebKit zero-day in late March 2022, CISA added it to the KEV on 2022-04-04, and EPSS puts the 30-day exploitation probability at 1.1%; no public PoC is known, but the KEV listing reflects real-world exploitation.

What to do: Upgrade to macOS Monterey 12.3.1, macOS Big Sur 11.6.6, or apply Security Update 2022-004 for Catalina; because this flaw is in CISA's Known Exploited Vulnerabilities catalog, treat patching as urgent. Inventory Macs for their installed macOS version (Apple menu > About This Mac) and confirm no unpatched machines remain. Until patched, limit local code execution from untrusted users or applications, since exploitation requires local access.

Affected
Apple macOS Montereyprior to 12.3.1
Apple macOS Big Surprior to 11.6.6
Apple macOS Catalina (Mac OS X)prior to Security Update 2022-004 Catalina
Estimated exposure
masstens of millions of Macs (macOS active install base on the order of 100 million devices) — macOS holds a double-digit share of the desktop OS market and Apple's reported active Mac install base is in the hundreds of millions, with the Catalina, Big Sur, and Monterey branches named in this advisory accounting for most supported…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Monterey 12.3.1, Security Update 2022-004 Catalina, macOS Big Sur 11.6.6. A local user may be able to read kernel memory.

CISA Known Exploited Vulnerability
Affected
Apple macOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
mac os x, macos
Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news