Out-of-bounds read in macOS - CVE-2022-22664
Published: March 14, 2022
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a boundary condition when processing files in GarageBand MIDI. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger an out-of-bounds read error and execute arbitrary code on the system.
Affected software
Apple GarageBand
Logic Pro X
How to mitigate CVE-2022-22664
Apple GarageBand - update to 10.4.6
Logic Pro X - update to 10.7.3