CVE-2022-22675: Apple macOS Out-of-Bounds Write Vulnerability
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.3.1, iOS 15.4.1 and iPadOS 15.4.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..
Other sources
apache. Multiple issues were addressed by updating apache to version 2.4.53.
— Apple
AppKit. A logic issue was addressed with improved validation.
— Apple
AppleAVD. An out-of-bounds write issue was addressed with improved bounds checking.
macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges.
— CISA
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in 11.6.6 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 15.5 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 8.6 - Upgrade
Upgrade
macOSto a version that resolves this vulnerability.Fixed in 12.3.1 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 15.4.1 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 15.4.1 - Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 15.4.1 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 15.4.1 - Upgrade
Upgrade
watchOSto a version that resolves this vulnerability.Fixed in 8.6 - Upgrade
Upgrade
macOS Big Surto a version that resolves this vulnerability.Fixed in 11.6.6 - Upgrade
Upgrade
macOS Montereyto a version that resolves this vulnerability.Fixed in 12.3.1 - Upgrade
Upgrade
apacheto a version that resolves this vulnerability.Fixed in 2.4.53
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2021-44224
- CVE-2021-44790
- CVE-2022-22719
- CVE-2022-22720
- CVE-2022-22721
- CVE-2022-22665
- CVE-2022-22675
- CVE-2022-22630
- CVE-2022-26751
- CVE-2022-26698
- CVE-2022-26697
- CVE-2022-22663
- CVE-2022-26721
- CVE-2022-26722
- CVE-2022-26763
- CVE-2022-22674
- CVE-2022-26720
- CVE-2022-26770
- CVE-2022-26756
- CVE-2022-26769
- CVE-2022-26748
- CVE-2022-26768
- CVE-2022-26714
- CVE-2022-26757
- CVE-2021-30946
- CVE-2022-26767
- CVE-2022-26706
- CVE-2022-32882
- CVE-2022-32790
- CVE-2022-26776
- CVE-2022-0778
- CVE-2022-23308
- CVE-2022-32794
- CVE-2022-26712
- CVE-2022-26746
- CVE-2022-26731
- CVE-2022-26766
- CVE-2022-26718
- CVE-2022-26723
- CVE-2022-26715
- CVE-2022-26728
- CVE-2022-26726
- CVE-2022-26755
- CVE-2021-4136
- CVE-2021-4166
- CVE-2021-4173
- CVE-2021-4187
- CVE-2021-4192
- CVE-2021-4193
- CVE-2021-46059
- CVE-2022-0128
- CVE-2022-22589
- CVE-2022-26745
- CVE-2022-26761
- CVE-2022-0530
- CVE-2018-25032
- CVE-2021-45444
- CVE-2022-26702
- CVE-2022-26724
- CVE-2022-26736
- CVE-2022-26737
- CVE-2022-26738
- CVE-2022-26739
- CVE-2022-26740
- CVE-2022-26711
- CVE-2022-26701
- CVE-2022-26771
- CVE-2022-26764
- CVE-2022-26765
- CVE-2022-26775
- CVE-2022-26708
- CVE-2022-26700
- CVE-2022-26709
- CVE-2022-26710
- CVE-2022-26717
- CVE-2022-26716
- CVE-2022-26719
Frequently Asked Questions
What is CVE-2022-22675?
CVE-2022-22675 is an out-of-bounds write vulnerability in Apple macOS.
How does CVE-2022-22675 affect Apple macOS?
CVE-2022-22675 affects Apple macOS by allowing an attacker to perform an out-of-bounds write.
Is CVE-2022-22675 actively exploited?
Apple is aware of a report that CVE-2022-22675 may have been actively exploited.
How can I fix CVE-2022-22675 on macOS Big Sur?
Update macOS Big Sur to version 11.6.6 to fix CVE-2022-22675.
How can I fix CVE-2022-22675 on macOS Monterey?
Update macOS Monterey to version 12.3.1 to fix CVE-2022-22675.