First published: Mon Mar 14 2022(Updated: )
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Logic Pro 10.7.3, GarageBand 10.4.6, macOS Monterey 12.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.
Credit: Brandon Perry Atredis PartnersBrandon Perry Atredis PartnersBrandon Perry Atredis Partners product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple GarageB | ||
Apple Logic Pro | <10.7.3 | 10.7.3 |
Apple macOS Monterey | <12.3 | 12.3 |
Apple GarageBand | <10.4.6 | |
Apple Logic Pro X | <10.7.3 | |
Apple macOS | <12.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-22664 is a vulnerability in GarageBand MIDI that allows an attacker to read data out of bounds.
CVE-2022-22664 affects Apple GarageBand, Apple Logic Pro up to version 10.7.3, and macOS Monterey up to version 12.3.
The severity of CVE-2022-22664 has not been specified.
To fix CVE-2022-22664, update Apple GarageBand to the latest version, update Apple Logic Pro to version 10.7.3, and update macOS Monterey to version 12.3.
You can find more information about CVE-2022-22664 on the Apple support page: [https://support.apple.com/en-us/HT213191](https://support.apple.com/en-us/HT213191)