CVE-2022-22586
published 2022-03-18CVE-2022-22586: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.2. A malicious application may be able to…
PriorityP353critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.93%
77.8th percentile
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.2. A malicious application may be able to execute arbitrary code with kernel privileges.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 12.2 | 12.2 |
| apple | macos | >= unspecified < 12.2 | 12.2 |
| apple | macos_monterey | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2022-22586: macOS Monterey 12.2
vendor_apple·2022-01-26·CVSS 9.8
CVE-2022-22586 [CRITICAL] CVE-2022-22586: macOS Monterey 12.2
Apple Security Update: About the security content of macOS Monterey 12.2
Product: macOS Monterey
Version: 12.2
CVE: CVE-2022-22586
Component: AMD Kernel
Impact: A malicious application may be able to execute arbitrary code with kernel privileges
Description: An out-of-bounds write issue was addressed with improved bounds checking.
GHSA
GHSA-hrqh-mqj9-qm2w: An out-of-bounds write issue was addressed with improved bounds checking
ghsa_unreviewed·2022-03-19
CVE-2022-22586 [CRITICAL] CWE-787 GHSA-hrqh-mqj9-qm2w: An out-of-bounds write issue was addressed with improved bounds checking
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.2. A malicious application may be able to execute arbitrary code with kernel privileges.
No detection rules found.
No public exploits indexed.
Sentinelone
10 Assumptions About macOS Security That Put Your Business At Risk
blogs_sentinelone·2022-02-07
10 Assumptions About macOS Security That Put Your Business At Risk
Macs are great, aren’t they? I have many. Aside from the two provided by my employer, I have five working Macs of my own, ranging from 2009 to 2021. I also run macOS on a number of virtual machines for research purposes. In fact, give me a few minutes and I could spin you up an instance of any version of macOS from 10.5.8 Leopard (circa 2008!) right through to the latest beta of macOS 12 Monterey. Yep, I’m an Apple nerd, a Mac geek, a macOS enthusiast, and I’ve spent over a decade now learning how Macs and macOS work. I’m also a Mac security researcher and having a catalogue of older versions of macOS is part of my arsenal of tools when it comes to understanding how to keep Macs and Mac users safe.
Most of my work nowadays revolves around identifying, tracking, and understanding Mac malwa
Sentinelone
10 Assumptions About macOS Security That Put Your Business At Risk
blogs_sentinelone·2022-02-07
10 Assumptions About macOS Security That Put Your Business At Risk
Macs are great, aren’t they? I have many. Aside from the two provided by my employer, I have five working Macs of my own, ranging from 2009 to 2021. I also run macOS on a number of virtual machines for research purposes. In fact, give me a few minutes and I could spin you up an instance of any version of macOS from 10.5.8 Leopard (circa 2008!) right through to the latest beta of macOS 12 Monterey. Yep, I’m an Apple nerd, a Mac geek, a macOS enthusiast, and I’ve spent over a decade now learning how Macs and macOS work. I’m also a Mac security researcher and having a catalogue of older versions of macOS is part of my arsenal of tools when it comes to understanding how to keep Macs and Mac users safe.
Most of my work nowadays revolves around identifying, tracking, and understanding Mac malwa
2022-03-18
Published