cbcvebase.
CVE-2022-22674
published 2022-05-26

CVE-2022-22674: An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in…

medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-04-25
Exploited in the wild
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Monterey 12.3.1, Security Update 2022-004 Catalina, macOS Big Sur 11.6.6. A local user may be able to read kernel memory.

Affected

10 ranges
VendorProductVersion rangeFixed in
applemac_os_x
applemac_os_x>= 10.15 < 10.15.710.15.7
applemacos>= 11.0 < 11.6.611.6.6
applemacos>= 12.0.0 < 12.3.112.3.1
applemacos>= unspecified < 12.312.3
applemacos>= unspecified < 20222022
applemacos>= unspecified < 11.611.6
applemacos_big_sur
applemacos_monterey
applesecurity_update_2022-004_catalina

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vulncheck5.5MEDIUM
cisa5.5MEDIUM