CVE-2022-22630
published 2023-06-23CVE-2022-22630: A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.6.6, macOS Monterey 12.3, Security Update…
PriorityP350critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.40%
69.7th percentile
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.6.6, macOS Monterey 12.3, Security Update 2022-004 Catalina. A remote user may cause an unexpected app termination or arbitrary code execution
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | macos | >= 11.0 < 11.6.6 | 11.6.6 |
| apple | macos | >= 12.0 < 12.3 | 12.3 |
| apple | macos | >= unspecified < 11.6 | 11.6 |
| apple | macos | >= unspecified < 12.3 | 12.3 |
| apple | macos | >= unspecified < 2022 | 2022 |
| apple | macos_big_sur | — | — |
| apple | macos_monterey | — | — |
| apple | security_update_2022-004_catalina | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2022-22630: Security Update 2022-004 Catalina
vendor_apple·2022-05-16·CVSS 9.8
CVE-2022-22630 [CRITICAL] CVE-2022-22630: Security Update 2022-004 Catalina
Apple Security Update: About the security content of Security Update 2022-004 Catalina
Product: Security Update 2022-004 Catalina
CVE: CVE-2022-22630
Component: AppleEvents
Impact: A remote user may cause an unexpected app termination or arbitrary code execution
Description: A use after free issue was addressed with improved memory management.
Apple
CVE-2022-22630: macOS Big Sur 11.6.6
vendor_apple·2022-05-16·CVSS 9.8
CVE-2022-22630 [CRITICAL] CVE-2022-22630: macOS Big Sur 11.6.6
Apple Security Update: About the security content of macOS Big Sur 11.6.6
Product: macOS Big Sur
Version: 11.6.6
CVE: CVE-2022-22630
Component: AppleEvents
Impact: A remote attacker may be able to cause an unexpected app termination or arbitrary code execution
Description: A use after free issue was addressed with improved memory management.
Apple
CVE-2022-22630: macOS Monterey 12.3
vendor_apple·2022-03-14·CVSS 9.8
CVE-2022-22630 [CRITICAL] CVE-2022-22630: macOS Monterey 12.3
Apple Security Update: About the security content of macOS Monterey 12.3
Product: macOS Monterey
Version: 12.3
CVE: CVE-2022-22630
Component: AppleEvents
Impact: A remote attacker may cause an unexpected app termination or arbitrary code execution
Description: A use after free issue was addressed with improved memory management.
VulDB
Apple macOS up to 12.2.1 Remote Event memory corruption (ZDI-22-1065 / EUVD-2022-27775)
vuldb·2026-04-28·CVSS 9.8
CVE-2022-22630 [CRITICAL] Apple macOS up to 12.2.1 Remote Event memory corruption (ZDI-22-1065 / EUVD-2022-27775)
A vulnerability identified as critical has been detected in Apple macOS. This issue affects some unknown processing of the component Remote Event Handler. The manipulation leads to memory corruption.
This vulnerability is referenced as CVE-2022-22630. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
You should upgrade the affected component.
GHSA
GHSA-rf7c-xh3f-99v4: A use after free issue was addressed with improved memory management
ghsa_unreviewed·2023-06-23
CVE-2022-22630 [CRITICAL] CWE-416 GHSA-rf7c-xh3f-99v4: A use after free issue was addressed with improved memory management
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.6.6, macOS Monterey 12.3, Security Update 2022-004 Catalina. A remote user may cause an unexpected app termination or arbitrary code execution
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-06-23
Published