CVE-2022-22674
KEVmassOut-of-Bounds Read in Apple macOS Kernel Discloses Kernel Memory
CISA: Apple macOS Out-of-Bounds Read Vulnerability
Apple's macOS kernel contained an out-of-bounds read (CWE-125) caused by insufficient input validation, which allowed a local user to read kernel memory. It is triggered by a local application or user on the machine interacting with the vulnerable kernel code path; there is no remote or unauthenticated attack vector. Successful exploitation discloses kernel memory (high confidentiality impact per the CVSS 5.5 local-attack score), but it does not by itself provide code execution or privilege escalation. All users of macOS Monterey, Big Sur, and Catalina who have not applied the March 2022 fixes are affected. The flaw is confirmed exploited in the wild: Apple shipped emergency patches alongside a WebKit zero-day in late March 2022, CISA added it to the KEV on 2022-04-04, and EPSS puts the 30-day exploitation probability at 1.1%; no public PoC is known, but the KEV listing reflects real-world exploitation.
What to do: Upgrade to macOS Monterey 12.3.1, macOS Big Sur 11.6.6, or apply Security Update 2022-004 for Catalina; because this flaw is in CISA's Known Exploited Vulnerabilities catalog, treat patching as urgent. Inventory Macs for their installed macOS version (Apple menu > About This Mac) and confirm no unpatched machines remain. Until patched, limit local code execution from untrusted users or applications, since exploitation requires local access.
| Apple macOS Monterey | prior to 12.3.1 |
| Apple macOS Big Sur | prior to 11.6.6 |
| Apple macOS Catalina (Mac OS X) | prior to Security Update 2022-004 Catalina |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Monterey 12.3.1, Security Update 2022-004 Catalina, macOS Big Sur 11.6.6. A local user may be able to read kernel memory.
- Affected
- Apple macOS
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- mac os x, macos
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N