CVE-2022-22584
published 2022-03-18CVE-2022-22584: A memory corruption issue was addressed with improved validation. This issue is fixed in tvOS 15.3, iOS 15.3 and iPadOS 15.3, watchOS 8.4, macOS Monterey 12.2…
PriorityP344high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.51%
71.5th percentile
A memory corruption issue was addressed with improved validation. This issue is fixed in tvOS 15.3, iOS 15.3 and iPadOS 15.3, watchOS 8.4, macOS Monterey 12.2. Processing a maliciously crafted file may lead to arbitrary code execution.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_15.3_and_ipados | — | — |
| apple | ios_and_ipados | >= unspecified < 15.3 | 15.3 |
| apple | ipados | < 15.3 | 15.3 |
| apple | iphone_os | < 15.3 | 15.3 |
| apple | macos | < 12.2 | 12.2 |
| apple | macos | >= unspecified < 12.2 | 12.2 |
| apple | macos_monterey | — | — |
| apple | tvos | < 15.3 | 15.3 |
| apple | tvos | — | — |
| apple | tvos | >= unspecified < 15.3 | 15.3 |
| apple | watchos | < 8.4 | 8.4 |
| apple | watchos | — | — |
| apple | watchos | >= unspecified < 8.4 | 8.4 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2022-22584: iOS 15.3 and iPadOS 15.3
vendor_apple·2022-01-26·CVSS 7.8
CVE-2022-22584 [HIGH] CVE-2022-22584: iOS 15.3 and iPadOS 15.3
Apple Security Update: About the security content of iOS 15.3 and iPadOS 15.3
Product: iOS 15.3 and iPadOS
Version: 15.3
CVE: CVE-2022-22584
Component: ColorSync
Impact: Processing a maliciously crafted file may lead to arbitrary code execution
Description: A memory corruption issue was addressed with improved validation.
Apple
CVE-2022-22584: tvOS 15.3
vendor_apple·2022-01-26·CVSS 7.8
CVE-2022-22584 [HIGH] CVE-2022-22584: tvOS 15.3
Apple Security Update: About the security content of tvOS 15.3
Product: tvOS
Version: 15.3
CVE: CVE-2022-22584
Component: ColorSync
Impact: Processing a maliciously crafted file may lead to arbitrary code execution
Description: A memory corruption issue was addressed with improved validation.
Apple
CVE-2022-22584: watchOS 8.4
vendor_apple·2022-01-26·CVSS 7.8
CVE-2022-22584 [HIGH] CVE-2022-22584: watchOS 8.4
Apple Security Update: About the security content of watchOS 8.4
Product: watchOS
Version: 8.4
CVE: CVE-2022-22584
Component: ColorSync
Impact: Processing a maliciously crafted file may lead to arbitrary code execution
Description: A memory corruption issue was addressed with improved validation.
Apple
CVE-2022-22584: macOS Monterey 12.2
vendor_apple·2022-01-26·CVSS 7.8
CVE-2022-22584 [HIGH] CVE-2022-22584: macOS Monterey 12.2
Apple Security Update: About the security content of macOS Monterey 12.2
Product: macOS Monterey
Version: 12.2
CVE: CVE-2022-22584
Component: ColorSync
Impact: Processing a maliciously crafted file may lead to arbitrary code execution
Description: A memory corruption issue was addressed with improved validation.
GHSA
GHSA-7qqr-c8r6-gcwc: A memory corruption issue was addressed with improved validation
ghsa_unreviewed·2022-03-19
CVE-2022-22584 [HIGH] CWE-787 GHSA-7qqr-c8r6-gcwc: A memory corruption issue was addressed with improved validation
A memory corruption issue was addressed with improved validation. This issue is fixed in tvOS 15.3, iOS 15.3 and iPadOS 15.3, watchOS 8.4, macOS Monterey 12.2. Processing a maliciously crafted file may lead to arbitrary code execution.
No detection rules found.
No public exploits indexed.
Sentinelone
10 Assumptions About macOS Security That Put Your Business At Risk
blogs_sentinelone·2022-02-07
10 Assumptions About macOS Security That Put Your Business At Risk
Macs are great, aren’t they? I have many. Aside from the two provided by my employer, I have five working Macs of my own, ranging from 2009 to 2021. I also run macOS on a number of virtual machines for research purposes. In fact, give me a few minutes and I could spin you up an instance of any version of macOS from 10.5.8 Leopard (circa 2008!) right through to the latest beta of macOS 12 Monterey. Yep, I’m an Apple nerd, a Mac geek, a macOS enthusiast, and I’ve spent over a decade now learning how Macs and macOS work. I’m also a Mac security researcher and having a catalogue of older versions of macOS is part of my arsenal of tools when it comes to understanding how to keep Macs and Mac users safe.
Most of my work nowadays revolves around identifying, tracking, and understanding Mac malwa
Sentinelone
10 Assumptions About macOS Security That Put Your Business At Risk
blogs_sentinelone·2022-02-07
10 Assumptions About macOS Security That Put Your Business At Risk
Macs are great, aren’t they? I have many. Aside from the two provided by my employer, I have five working Macs of my own, ranging from 2009 to 2021. I also run macOS on a number of virtual machines for research purposes. In fact, give me a few minutes and I could spin you up an instance of any version of macOS from 10.5.8 Leopard (circa 2008!) right through to the latest beta of macOS 12 Monterey. Yep, I’m an Apple nerd, a Mac geek, a macOS enthusiast, and I’ve spent over a decade now learning how Macs and macOS work. I’m also a Mac security researcher and having a catalogue of older versions of macOS is part of my arsenal of tools when it comes to understanding how to keep Macs and Mac users safe.
Most of my work nowadays revolves around identifying, tracking, and understanding Mac malwa
https://support.apple.com/en-us/HT213053https://support.apple.com/en-us/HT213054https://support.apple.com/en-us/HT213057https://support.apple.com/en-us/HT213059https://support.apple.com/en-us/HT213053https://support.apple.com/en-us/HT213054https://support.apple.com/en-us/HT213057https://support.apple.com/en-us/HT213059
2022-03-18
Published