Out-of-bounds write in macOS - CVE-2022-22675

 

Out-of-bounds write in macOS - CVE-2022-22675

Published: April 1, 2022


Vulnerability identifier: #VU61773
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22675
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error within the AppleAVD subsystem. A local user can run a specially crafted program to trigger an out-of-bounds write and execute arbitrary code with kernel privileges.

Note, the vulnerability is being actively exploited in the wild.


Affected software

macOS
watchOS
iPadOS
Apple iOS
tvOS

How to mitigate CVE-2022-22675

Install updates from vendor's website.

macOS - addressed in versions 12.3.1 21E258, 11.6.6 20G624
watchOS - update to 8.6 19T572
iPadOS - update to 15.4.1 19E258
Apple iOS - update to 15.4.1 19E258
tvOS - update to 15.5 19L570

External References

Related Security Bulletins