peter bassill · operator
$ cve CVE-2022-22674 JSON

CVE-2022-22674 KEV

5.5
MEDIUM · CVSS 3.1 · EPSS 1.1% (pctl 65)

Patch first

On CISA KEV — known exploited in the wild, due 2022-04-25.

Description

An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Monterey 12.3.1, Security Update 2022-004 Catalina, macOS Big Sur 11.6.6. A local user may be able to read kernel memory.

Scoring

CVSS5.5 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS1.13% — more likely to be exploited than 65% of all CVEs
WeaknessCWE-125
On CISA KEVyes — remediate by 2022-04-25
Public exploitnone known
Published2022-05-26
Last modified2026-06-17

CISA KEV

NameApple macOS Out-of-Bounds Read Vulnerability
Added2022-04-04
Due2022-04-25
Vendor / productApple / macOS
Ransomware usenone reported

Affected (2)

VendorProduct
applemac os x
applemacos

References

→ the Explorer  ·  watch your stack  ·  NVD