ZeroHour

CVE-2022-22675

KEVmass

Out-of-Bounds Write in Apple macOS/iOS Kernel Allows Arbitrary Code Execution

CISA: Apple macOS Out-of-Bounds Write Vulnerability

CVSS 3.1
7.8 high
EPSS
12%p96
Published
()
KEV added
AI analysis

CVE-2022-22675 is an out-of-bounds write vulnerability (CWE-787) in the Apple kernel, addressed through improved bounds checking. It is triggered locally — the CVSS vector shows a local attack vector with user interaction, meaning an application running on the device can trigger the memory corruption. Successful exploitation allows an application to execute arbitrary code with kernel privileges, giving the attacker full control over the affected device. Users of iPhone, iPad, Mac, Apple TV, and Apple Watch running versions prior to the fixed releases are affected. Apple reported that the issue may have been actively exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-04-04.

What to do: Update to iOS/iPadOS 15.4.1, macOS Monterey 12.3.1 or macOS Big Sur 11.6.6, tvOS 15.5, and watchOS 8.6 as required by CISA. Because the flaw is exploited in the wild and requires only a malicious local application, prioritize patching user-facing iPhone, iPad, and Mac fleets first. There is no public PoC; verify installed OS versions on managed devices and confirm remediation after the updates are applied.

Affected
apple iphone_os (iOS)prior to 15.4.1
apple ipadosprior to 15.4.1
apple macos (Big Sur)prior to 11.6.6
apple macos (Monterey)prior to 12.3.1
apple tvosprior to 15.5
apple watchosprior to 8.6
Estimated exposure
mass≈1 billion+ active Apple devices across iPhone, iPad, Mac, Apple TV, and Apple Watch — Apple's active installed base publicly exceeds one billion devices, and the flaw affected all major Apple operating systems prior to the April/May 2022 updates, though the share still on vulnerable versions today is unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.3.1, iOS 15.4.1 and iPadOS 15.4.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..

CISA Known Exploited Vulnerability
Affected
Apple macOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
ipados, iphone os, macos, tvos, watchos
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news