#VU60029 Out-of-bounds read in macOS - CVE-2022-22579
Published: January 26, 2022 / Updated: February 16, 2022
macOS
Apple Inc.
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a boundary condition in Model I/O when processing STL files. A remote attacker can create a specially crafted STL file, trick the victim into opening it, trigger an out-of-bounds read error and read contents of memory or execute arbitrary code on the system.