cbcvebase.
CVE-2022-22674
published 2022-05-26

CVE-2022-22674: An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in…

PriorityP276medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-04-25
Exploited in the wild
EPSS
1.13%
62.7th percentile
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Monterey 12.3.1, Security Update 2022-004 Catalina, macOS Big Sur 11.6.6. A local user may be able to read kernel memory.

Affected

10 ranges
VendorProductVersion rangeFixed in
applemac_os_x
applemac_os_x>= 10.15 < 10.15.710.15.7
applemacos>= 11.0 < 11.6.611.6.6
applemacos>= 12.0.0 < 12.3.112.3.1
applemacos>= unspecified < 12.312.3
applemacos>= unspecified < 20222022
applemacos>= unspecified < 11.611.6
applemacos_big_sur
applemacos_monterey
applesecurity_update_2022-004_catalina

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerable component is the Intel Graphics Driver (kernel extension) on macOS; monitor for suspicious applications invoking Intel Graphics Driver IOCTLs or triggering out-of-bounds reads in the graphics driver kernel space.
  • Apple confirmed active in-the-wild exploitation of this vulnerability; treat any unpatched macOS Monterey, Big Sur, or Catalina system as at risk and prioritize detection of local privilege/information-disclosure abuse chains targeting the graphics driver.
  • CISA added this to the Known Exploited Vulnerabilities catalog with a remediation due date of 2022-04-25, indicating confirmed exploitation in the wild; use this as a prioritization signal for endpoint detection on macOS fleets.
  • ·The vulnerability affects three distinct macOS versions/update tracks: macOS Monterey (fixed in 12.3.1), macOS Big Sur (fixed in 11.6.6), and macOS Catalina (fixed in Security Update 2022-004 Catalina). Detection and patching logic must account for all three.
  • ·The affected component is labelled 'Intel Graphics Driver' on Monterey but 'Graphics Drivers' (broader) on Big Sur and Catalina advisories — detection rules targeting the specific kext should account for possible naming differences across OS versions.

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:C/I:N/A:N
vulncheck5.5MEDIUM
cisa5.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.