CVE-2022-22674: Apple macOS Out-of-Bounds Read Vulnerability
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Monterey 12.3.1, Security Update 2022-004 Catalina, macOS Big Sur 11.6.6. A local user may be able to read kernel memory.
Other sources
apache. Multiple issues were addressed by updating apache to version 2.4.53.
— Apple
AppKit. A logic issue was addressed with improved validation.
— Apple
AppleAVD. An out-of-bounds write issue was addressed with improved bounds checking.
— Apple
AppleEvents. A use after free issue was addressed with improved memory management.
— Apple
AppleGraphicsControl. A memory corruption issue was addressed with improved input validation.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in 11.6.6 - Upgrade
Upgrade
macOSto a version that resolves this vulnerability.Fixed in 12.3.1 - Upgrade
Upgrade
macOS Montereyto a version that resolves this vulnerability.Fixed in 12.3.1 - Upgrade
Upgrade
macOS Big Surto a version that resolves this vulnerability.Fixed in 11.6.6 - Upgrade
Upgrade
macOS Catalinato a version that resolves this vulnerability.Patch Security Update 2022-004 Catalina - Upgrade
Upgrade
apacheto a version that resolves this vulnerability.Fixed in 2.4.53
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2021-44224
- CVE-2021-44790
- CVE-2022-22719
- CVE-2022-22720
- CVE-2022-22721
- CVE-2022-22665
- CVE-2022-22675
- CVE-2022-22630
- CVE-2022-26751
- CVE-2022-26698
- CVE-2022-26697
- CVE-2022-22663
- CVE-2022-26721
- CVE-2022-26722
- CVE-2022-26763
- CVE-2022-22674
- CVE-2022-26720
- CVE-2022-26770
- CVE-2022-26756
- CVE-2022-26769
- CVE-2022-26748
- CVE-2022-26768
- CVE-2022-26714
- CVE-2022-26757
- CVE-2021-30946
- CVE-2022-26767
- CVE-2022-26706
- CVE-2022-32882
- CVE-2022-32790
- CVE-2022-26776
- CVE-2022-0778
- CVE-2022-23308
- CVE-2022-32794
- CVE-2022-26712
- CVE-2022-26746
- CVE-2022-26731
- CVE-2022-26766
- CVE-2022-26718
- CVE-2022-26723
- CVE-2022-26715
- CVE-2022-26728
- CVE-2022-26726
- CVE-2022-26755
- CVE-2021-4136
- CVE-2021-4166
- CVE-2021-4173
- CVE-2021-4187
- CVE-2021-4192
- CVE-2021-4193
- CVE-2021-46059
- CVE-2022-0128
- CVE-2022-22589
- CVE-2022-26745
- CVE-2022-26761
- CVE-2022-0530
- CVE-2018-25032
- CVE-2021-45444
- CVE-2022-26775
- CVE-2022-26727
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-22674.
What is the title of the vulnerability?
The title of the vulnerability is Apple macOS Out-of-Bounds Read Vulnerability.
What is the description of the vulnerability?
The description of the vulnerability is an out-of-bounds read issue in the Intel Graphics Driver, which may lead to the disclosure of kernel memory and has been addressed with improved input validation.
Which software versions are affected by the vulnerability?
The vulnerability affects Apple macOS Monterey up to version 12.3.1, Apple macOS Big Sur up to version 11.6.6, and Apple macOS Catalina.
Has this vulnerability been actively exploited?
Apple is aware of a report that this vulnerability may have been actively exploited.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the Apple support website. Please refer to the following links: [link1](https://support.apple.com/en-us/HT213255), [link2](https://support.apple.com/en-us/HT213220), [link3](https://support.apple.com/en-us/HT213256).