CVE-2022-22600
published 2022-03-18CVE-2022-22600: The issue was addressed with improved permissions logic. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3, watchOS 8.5. A…
PriorityP424medium5.5CVSS 3.1
AVLACLPRNUIRSUCNIHAN
EPSS
1.63%
73.5th percentile
The issue was addressed with improved permissions logic. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3, watchOS 8.5. A malicious application may be able to bypass certain Privacy preferences.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_15.4_and_ipados | — | — |
| apple | ios_and_ipados | >= unspecified < 15.4 | 15.4 |
| apple | ipados | < 15.4 | 15.4 |
| apple | iphone_os | < 15.4 | 15.4 |
| apple | macos | < 12.3 | 12.3 |
| apple | macos | >= unspecified < 12.3 | 12.3 |
| apple | macos_monterey | — | — |
| apple | tvos | < 15.4 | 15.4 |
| apple | tvos | — | — |
| apple | tvos | >= unspecified < 15.4 | 15.4 |
| apple | watchos | < 8.5 | 8.5 |
| apple | watchos | — | — |
| apple | watchos | >= unspecified < 8.5 | 8.5 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
cisa7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Linux Kernel Privilege Escalation Vulnerability
cisa·2022-04-11·CVSS 7.0
CVE-2021-22600 [MEDIUM] CWE-415 Linux Kernel Privilege Escalation Vulnerability
Vulnerability: Linux Kernel Privilege Escalation Vulnerability
Affected: Linux Kernel
Linux Kernel contains a flaw in the packet socket (AF_PACKET) implementation which could lead to incorrectly freeing memory. A local user could exploit this for denial-of-service (DoS) or possibly for privilege escalation.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-22600
Remediation Due Date: 2022-05-02
Apple
CVE-2022-22600: iOS 15.4 and iPadOS 15.4
vendor_apple·2022-03-14·CVSS 5.5
CVE-2022-22600 [MEDIUM] CVE-2022-22600: iOS 15.4 and iPadOS 15.4
Apple Security Update: About the security content of iOS 15.4 and iPadOS 15.4
Product: iOS 15.4 and iPadOS
Version: 15.4
CVE: CVE-2022-22600
Component: Sandbox
Impact: A malicious application may be able to bypass certain Privacy preferences
Description: The issue was addressed with improved permissions logic.
Apple
CVE-2022-22600: macOS Monterey 12.3
vendor_apple·2022-03-14·CVSS 5.5
CVE-2022-22600 [MEDIUM] CVE-2022-22600: macOS Monterey 12.3
Apple Security Update: About the security content of macOS Monterey 12.3
Product: macOS Monterey
Version: 12.3
CVE: CVE-2022-22600
Component: Sandbox
Impact: A malicious application may be able to bypass certain Privacy preferences
Description: The issue was addressed with improved permissions logic.
Apple
CVE-2022-22600: watchOS 8.5
vendor_apple·2022-03-14·CVSS 5.5
CVE-2022-22600 [MEDIUM] CVE-2022-22600: watchOS 8.5
Apple Security Update: About the security content of watchOS 8.5
Product: watchOS
Version: 8.5
CVE: CVE-2022-22600
Component: Sandbox
Impact: A malicious application may be able to bypass certain Privacy preferences
Description: The issue was addressed with improved permissions logic.
Apple
CVE-2022-22600: tvOS 15.4
vendor_apple·2022-03-14·CVSS 5.5
CVE-2022-22600 [MEDIUM] CVE-2022-22600: tvOS 15.4
Apple Security Update: About the security content of tvOS 15.4
Product: tvOS
Version: 15.4
CVE: CVE-2022-22600
Component: Sandbox
Impact: A malicious application may be able to bypass certain Privacy preferences
Description: The issue was addressed with improved permissions logic.
Project0
An Autopsy on a Zombie In-the-Wild 0-day - Project Zero
project_zero·2022-06-01·CVSS 8.8
CVE-2022-22600 [HIGH] An Autopsy on a Zombie In-the-Wild 0-day - Project Zero
Posted by Maddie Stone, Google Project Zero
Whenever there’s a new in-the-wild 0-day disclosed, I’m very interested in understanding the root cause of the bug. This allows us to then understand if it was fully fixed, look for variants, and brainstorm new mitigations. This blog is the story of a “zombie” Safari 0-day and how it came back from the dead to be disclosed as exploited in-the-wild in 2022. CVE-2022-22620 was initially fixed in 2013, reintroduced in 2016, and then disclosed as exploited in-the-wild in 2022. If you’re interested in the full root cause analysis for CVE-2022-22620, we’ve published it here.
In the 2020 Year in Review of 0-days exploited in the wild, I wrote how 25% of all 0-days detected and disclosed as exploited in-the-wild in 2020 were variants of previou
GHSA
GHSA-6wc2-gxhg-9rx4: The issue was addressed with improved permissions logic
ghsa_unreviewed·2022-03-19
CVE-2022-22600 [MEDIUM] GHSA-6wc2-gxhg-9rx4: The issue was addressed with improved permissions logic
The issue was addressed with improved permissions logic. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3, watchOS 8.5. A malicious application may be able to bypass certain Privacy preferences.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://support.apple.com/en-us/HT213182https://support.apple.com/en-us/HT213183https://support.apple.com/en-us/HT213186https://support.apple.com/en-us/HT213193https://support.apple.com/en-us/HT213182https://support.apple.com/en-us/HT213183https://support.apple.com/en-us/HT213186https://support.apple.com/en-us/HT213193
2022-03-18
Published