Buffer overflow in macOS - CVE-2022-22640
Published: March 14, 2022
Vulnerability identifier: #VU61317
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22640
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error in macOS kernel. A local user can run a specially crafted program to trigger memory corruption and execute arbitrary code on the system.
Affected software
macOS
watchOS
Apple iOS
iPadOS
tvOS
watchOS
Apple iOS
iPadOS
tvOS
How to mitigate CVE-2022-22640
Install updates from vendor's website.
macOS - update to 12.3 21E230
watchOS - update to 8.5 19T242
Apple iOS - update to 15.4 19E241
iPadOS - update to 15.4 19E241
tvOS - update to 15.4 19L440
watchOS - update to 8.5 19T242
Apple iOS - update to 15.4 19E241
iPadOS - update to 15.4 19E241
tvOS - update to 15.4 19L440