First published: Wed Jan 26 2022(Updated: )
IOMobileFrameBuffer. A memory corruption issue was addressed with improved input validation.
Credit: an anonymous researcher Meysam Firouzi @R00tkitSMM MBitionSiddharth Aeri @b1n4r1b01 an anonymous researcher Meysam Firouzi @R00tkitSMM MBitionSiddharth Aeri @b1n4r1b01 an anonymous researcher Meysam Firouzi @R00tkitSMM MBitionSiddharth Aeri @b1n4r1b01 product-security@apple.com product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS Monterey | <12.2 | 12.2 |
Apple macOS Big Sur | <11.6.3 | 11.6.3 |
Apple iOS | <15.3 | 15.3 |
Apple iPadOS | <15.3 | 15.3 |
Apple iPadOS | <15.3 | |
Apple iPhone OS | <15.3 | |
Apple macOS | <11.6.3 | |
Apple macOS | >=12.0<12.2 | |
Apple iOS and macOS | ||
<15.3 | ||
<15.3 | ||
<11.6.3 | ||
>=12.0<12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-22587 is a memory corruption vulnerability in Apple IOMobileFrameBuffer that allows a malicious application to execute arbitrary code with kernel privileges.
CVE-2022-22587 affects Apple iOS and macOS, specifically macOS Big Sur (up to version 11.6.3), iOS (up to version 15.3), iPadOS (up to version 15.3), and macOS Monterey (up to version 12.2).
CVE-2022-22587 is a memory corruption vulnerability, which is considered a high-severity issue.
To fix the vulnerability in macOS Big Sur, update to version 11.6.3 or later.
To fix the vulnerability in iOS, update to version 15.3 or later.
You can find more information about CVE-2022-22587 on the Apple support website.