CVE-2022-22674
published 2022-05-26CVE-2022-22674: An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in…
PriorityP276medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-04-25
Exploited in the wild
EPSS
1.13%
62.7th percentile
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Monterey 12.3.1, Security Update 2022-004 Catalina, macOS Big Sur 11.6.6. A local user may be able to read kernel memory.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | mac_os_x | >= 10.15 < 10.15.7 | 10.15.7 |
| apple | macos | >= 11.0 < 11.6.6 | 11.6.6 |
| apple | macos | >= 12.0.0 < 12.3.1 | 12.3.1 |
| apple | macos | >= unspecified < 12.3 | 12.3 |
| apple | macos | >= unspecified < 2022 | 2022 |
| apple | macos | >= unspecified < 11.6 | 11.6 |
| apple | macos_big_sur | — | — |
| apple | macos_monterey | — | — |
| apple | security_update_2022-004_catalina | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerable component is the Intel Graphics Driver (kernel extension) on macOS; monitor for suspicious applications invoking Intel Graphics Driver IOCTLs or triggering out-of-bounds reads in the graphics driver kernel space. ↗
- →Apple confirmed active in-the-wild exploitation of this vulnerability; treat any unpatched macOS Monterey, Big Sur, or Catalina system as at risk and prioritize detection of local privilege/information-disclosure abuse chains targeting the graphics driver. ↗
- →CISA added this to the Known Exploited Vulnerabilities catalog with a remediation due date of 2022-04-25, indicating confirmed exploitation in the wild; use this as a prioritization signal for endpoint detection on macOS fleets. ↗
- ·The vulnerability affects three distinct macOS versions/update tracks: macOS Monterey (fixed in 12.3.1), macOS Big Sur (fixed in 11.6.6), and macOS Catalina (fixed in Security Update 2022-004 Catalina). Detection and patching logic must account for all three. ↗
- ·The affected component is labelled 'Intel Graphics Driver' on Monterey but 'Graphics Drivers' (broader) on Big Sur and Catalina advisories — detection rules targeting the specific kext should account for possible naming differences across OS versions. ↗
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:C/I:N/A:N
vulncheck5.5MEDIUM
cisa5.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2022-22674: Security Update 2022-004 Catalina
vendor_apple·2022-05-16·CVSS 5.5
CVE-2022-22674 [MEDIUM] CVE-2022-22674: Security Update 2022-004 Catalina
Apple Security Update: About the security content of Security Update 2022-004 Catalina
Product: Security Update 2022-004 Catalina
CVE: CVE-2022-22674
Component: Graphics Drivers
Impact: A local user may be able to read kernel memory
Description: An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation.
Apple
CVE-2022-22674: macOS Big Sur 11.6.6
vendor_apple·2022-05-16·CVSS 5.5
CVE-2022-22674 [MEDIUM] CVE-2022-22674: macOS Big Sur 11.6.6
Apple Security Update: About the security content of macOS Big Sur 11.6.6
Product: macOS Big Sur
Version: 11.6.6
CVE: CVE-2022-22674
Component: Graphics Drivers
Impact: A local user may be able to read kernel memory
Description: An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation.
CISA
Apple macOS Out-of-Bounds Read Vulnerability
cisa·2022-04-04·CVSS 5.5
CVE-2022-22674 [MEDIUM] CWE-20 Apple macOS Out-of-Bounds Read Vulnerability
Vulnerability: Apple macOS Out-of-Bounds Read Vulnerability
Affected: Apple macOS
macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-22674
Remediation Due Date: 2022-04-25
Apple
CVE-2022-22674: macOS Monterey 12.3.1
vendor_apple·2022-03-31·CVSS 5.5
CVE-2022-22674 [MEDIUM] CVE-2022-22674: macOS Monterey 12.3.1
Apple Security Update: About the security content of macOS Monterey 12.3.1
Product: macOS Monterey
Version: 12.3.1
CVE: CVE-2022-22674
Component: Intel Graphics Driver
Impact: An application may be able to read kernel memory
Description: An out-of-bounds read issue may lead to the disclosure of kernel memory and was addressed with improved input validation. Apple is aware of a report that this issue may have been actively exploited.
GHSA
GHSA-mj8g-26g5-c9fp: An out-of-bounds read issue existed that led to the disclosure of kernel memory
ghsa_unreviewed·2022-05-27
CVE-2022-22674 [MEDIUM] CWE-125 GHSA-mj8g-26g5-c9fp: An out-of-bounds read issue existed that led to the disclosure of kernel memory
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Monterey 12.3.1, Security Update 2022-004 Catalina, macOS Big Sur 11.6.6. A local user may be able to read kernel memory.
VulnCheck
Apple macOS Out-of-Bounds Read Vulnerability
vulncheck·2022·CVSS 5.5
CVE-2022-22674 [MEDIUM] CWE-20 Apple macOS Out-of-Bounds Read Vulnerability
Apple macOS Out-of-Bounds Read Vulnerability
macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory.
Affected: Apple MacOS X
Required Action: Apply updates per vendor instructions.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://raw.githubusercontent.com/blackorbird/APT_REPORT/master/summary/2023/360_APT_Annual_Research_Report_2022.pdf
Remediation Due: 2022-04-25
No detection rules found.
No public exploits indexed.
https://support.apple.com/en-us/HT213220https://support.apple.com/en-us/HT213255https://support.apple.com/en-us/HT213256https://support.apple.com/en-us/HT213220https://support.apple.com/en-us/HT213255https://support.apple.com/en-us/HT213256https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22674
2022-05-26
Published
2022-04-04
Added to CISA KEV
Exploited in the wild