CVE-2022-22587: Apple Memory Corruption Vulnerability
IOMobileFrameBuffer. A memory corruption issue was addressed with improved input validation.
Other sources
Apple IOMobileFrameBuffer contains a memory corruption vulnerability which can allow a malicious application to execute arbitrary code with kernel privileges.
— CISA
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, macOS Big Sur 11.6.3, macOS Monterey 12.2. A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in 11.6.3 - Upgrade
Upgrade
macOSto a version that resolves this vulnerability.Fixed in 12.2 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 15.3 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 15.3 - Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 15.3 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 15.3 - Upgrade
Upgrade
macOS Big Surto a version that resolves this vulnerability.Fixed in 11.6.3 - Upgrade
Upgrade
macOS Montereyto a version that resolves this vulnerability.Fixed in 12.2
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2022-22587?
CVE-2022-22587 is a memory corruption vulnerability in Apple IOMobileFrameBuffer that allows a malicious application to execute arbitrary code with kernel privileges.
Which software products are affected by CVE-2022-22587?
CVE-2022-22587 affects Apple iOS and macOS, specifically macOS Big Sur (up to version 11.6.3), iOS (up to version 15.3), iPadOS (up to version 15.3), and macOS Monterey (up to version 12.2).
How severe is the vulnerability CVE-2022-22587?
CVE-2022-22587 is a memory corruption vulnerability, which is considered a high-severity issue.
How can I fix the vulnerability in macOS Big Sur?
To fix the vulnerability in macOS Big Sur, update to version 11.6.3 or later.
How can I fix the vulnerability in iOS?
To fix the vulnerability in iOS, update to version 15.3 or later.
Where can I find more information about CVE-2022-22587?
You can find more information about CVE-2022-22587 on the Apple support website.