First published: Thu Mar 31 2022(Updated: )
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Monterey 12.3.1, Security Update 2022-004 Catalina, macOS Big Sur 11.6.6. A local user may be able to read kernel memory.
Credit: an anonymous researcher an anonymous researcher product-security@apple.com an anonymous researcher product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS Monterey | <12.3.1 | 12.3.1 |
Apple Catalina | ||
Apple Mac OS X | >=10.15<10.15.7 | |
Apple Mac OS X | =10.15.7 | |
Apple Mac OS X | =10.15.7-security_update_2020 | |
Apple Mac OS X | =10.15.7-security_update_2020-001 | |
Apple Mac OS X | =10.15.7-security_update_2020-005 | |
Apple Mac OS X | =10.15.7-security_update_2020-007 | |
Apple Mac OS X | =10.15.7-security_update_2021-001 | |
Apple Mac OS X | =10.15.7-security_update_2021-002 | |
Apple Mac OS X | =10.15.7-security_update_2021-003 | |
Apple Mac OS X | =10.15.7-security_update_2021-006 | |
Apple Mac OS X | =10.15.7-security_update_2021-007 | |
Apple Mac OS X | =10.15.7-security_update_2021-008 | |
Apple Mac OS X | =10.15.7-security_update_2022-001 | |
Apple Mac OS X | =10.15.7-security_update_2022-002 | |
Apple Mac OS X | =10.15.7-security_update_2022-003 | |
Apple Mac OS X | =10.15.7-supplemental_update | |
Apple macOS | >=11.0<11.6.6 | |
Apple macOS | >=12.0.0<12.3.1 | |
Apple macOS Big Sur | <11.6.6 | 11.6.6 |
Apple macOS | ||
>=10.15<10.15.7 | ||
=10.15.7 | ||
=10.15.7-security_update_2020 | ||
=10.15.7-security_update_2020-001 | ||
=10.15.7-security_update_2020-005 | ||
=10.15.7-security_update_2020-007 | ||
=10.15.7-security_update_2021-001 | ||
=10.15.7-security_update_2021-002 | ||
=10.15.7-security_update_2021-003 | ||
=10.15.7-security_update_2021-006 | ||
=10.15.7-security_update_2021-007 | ||
=10.15.7-security_update_2021-008 | ||
=10.15.7-security_update_2022-001 | ||
=10.15.7-security_update_2022-002 | ||
=10.15.7-security_update_2022-003 | ||
=10.15.7-supplemental_update | ||
>=11.0<11.6.6 | ||
>=12.0.0<12.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID is CVE-2022-22674.
The title of the vulnerability is Apple macOS Out-of-Bounds Read Vulnerability.
The description of the vulnerability is an out-of-bounds read issue in the Intel Graphics Driver, which may lead to the disclosure of kernel memory and has been addressed with improved input validation.
The vulnerability affects Apple macOS Monterey up to version 12.3.1, Apple macOS Big Sur up to version 11.6.6, and Apple macOS Catalina.
Apple is aware of a report that this vulnerability may have been actively exploited.
You can find more information about this vulnerability on the Apple support website. Please refer to the following links: [link1](https://support.apple.com/en-us/HT213255), [link2](https://support.apple.com/en-us/HT213220), [link3](https://support.apple.com/en-us/HT213256).