MEDIUM
CVE-2022-22674
CVSS
5.5
KEV
Description
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Monterey 12.3.1, Security Update 2022-004 Catalina, macOS Big Sur 11.6.6. A local user may be able to read kernel memory.
Summary dbcve.org
This is an out-of-bounds read vulnerability in macOS that allows a local unprivileged user to read kernel memory. The flaw was in input validation that did not properly bounds-check certain operations, enabling kernel memory contents to be disclosed to user space.
Mitigation
Apply the appropriate Apple security update: macOS Monterey 12.3.1, Security Update 2022-004 for Catalina, or macOS Big Sur 11.6.6 or later, depending on the installed OS version.
Weakness (CWE)
CWE-125
Out-of-bounds Read
EPSS Score
1.13%
Probability of exploitation in next 30 days
65th percentile
References
https://support.apple.com/en-us/HT213220
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213255
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213256
Release Notes, Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22674
Third Party Advisory, US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.