CVE-2022-22627: High severity apple macos vulnerability
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. Processing a maliciously crafted AppleScript binary may result in unexpected application termination or disclosure of process memory.
Other sources
AppleScript. An out-of-bounds read was addressed with improved bounds checking.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2022-22633
- CVE-2022-22665
- CVE-2022-22631
- CVE-2022-22648
- CVE-2022-22627
- CVE-2022-22626
- CVE-2022-22625
- CVE-2022-22597
- CVE-2022-22616
- CVE-2022-26691
- CVE-2022-46706
- CVE-2022-22661
- CVE-2022-22613
- CVE-2022-22615
- CVE-2022-22614
- CVE-2022-22638
- CVE-2022-22632
- CVE-2022-22647
- CVE-2022-22656
- CVE-2022-22672
- CVE-2022-22617
- CVE-2022-26688
- CVE-2022-22650
- CVE-2022-22599
- CVE-2022-22651
- CVE-2022-22662
- CVE-2022-22582
- CVE-2022-22589
- CVE-2022-22669
- CVE-2022-22630
- CVE-2022-22663
- CVE-2021-22946
- CVE-2021-22947
- CVE-2021-22945
- CVE-2022-22643
- CVE-2022-22657
- CVE-2022-22664
- CVE-2021-30977
- CVE-2022-22611
- CVE-2022-22612
- CVE-2022-22641
- CVE-2022-22640
- CVE-2021-30946
- CVE-2021-36976
- CVE-2022-21658
- CVE-2022-22644
- CVE-2022-26690
- CVE-2022-22609
- CVE-2022-22655
- CVE-2022-22600
- CVE-2022-22639
- CVE-2022-22660
- CVE-2022-22621
- CVE-2021-4136
- CVE-2021-4166
- CVE-2021-4173
- CVE-2021-4187
- CVE-2021-4192
- CVE-2021-4193
- CVE-2021-46059
- CVE-2022-0128
- CVE-2022-0156
- CVE-2022-0158
- CVE-2021-30918
- CVE-2022-22610
- CVE-2022-22624
- CVE-2022-22628
- CVE-2022-22629
- CVE-2022-22637
- CVE-2022-22668
Frequently Asked Questions
What is CVE-2022-22627?
CVE-2022-22627 is a vulnerability in AppleScript that allows for an out-of-bounds read, which has been fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, and Security Update 2022-003 Catalina.
What is the severity of CVE-2022-22627?
The severity of CVE-2022-22627 is high, with a CVSS score of 7.1.
How does CVE-2022-22627 impact affected software?
Processing a maliciously crafted AppleScript binary may result in unexpected application termination or disclosure of process memory.
Which versions of macOS are affected by CVE-2022-22627?
CVE-2022-22627 affects macOS Big Sur (up to and excluding 11.6.5), macOS Monterey (up to and excluding 12.3), and macOS Catalina.
How can I fix CVE-2022-22627?
To fix CVE-2022-22627, update your macOS to the latest version available: macOS Big Sur 11.6.5, macOS Monterey 12.3, or install Security Update 2022-003 for macOS Catalina.