CVE-2022-42821
published 2022-12-15CVE-2022-42821: A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.2, macOS Big Sur 11.7.2, macOS Ventura 13. An app may bypass…
PriorityP428medium5.5CVSS 3.1
AVLACLPRNUIRSUCNIHAN
EPSS
3.90%
89.0th percentile
A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.2, macOS Big Sur 11.7.2, macOS Ventura 13. An app may bypass Gatekeeper checks.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | >= 11.0 < 11.7.2 | 11.7.2 |
| apple | macos | >= 12.0.0 < 12.6.2 | 12.6.2 |
| apple | macos | >= unspecified < 11.7 | 11.7 |
| apple | macos | >= unspecified < 13 | 13 |
| apple | macos | >= unspecified < 12.6 | 12.6 |
| apple | macos_big_sur | — | — |
| apple | macos_monterey | — | — |
| apple | macos_ventura | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2022-42821: macOS Monterey 12.6.2
vendor_apple·2022-12-13·CVSS 5.5
CVE-2022-42821 [MEDIUM] CVE-2022-42821: macOS Monterey 12.6.2
Apple Security Update: About the security content of macOS Monterey 12.6.2
Product: macOS Monterey
Version: 12.6.2
CVE: CVE-2022-42821
Component: BOM
Impact: An app may bypass Gatekeeper checks
Description: A logic issue was addressed with improved checks.
Apple
CVE-2022-42821: macOS Big Sur 11.7.2
vendor_apple·2022-12-13·CVSS 5.5
CVE-2022-42821 [MEDIUM] CVE-2022-42821: macOS Big Sur 11.7.2
Apple Security Update: About the security content of macOS Big Sur 11.7.2
Product: macOS Big Sur
Version: 11.7.2
CVE: CVE-2022-42821
Component: BOM
Impact: An app may bypass Gatekeeper checks
Description: A logic issue was addressed with improved checks.
Apple
CVE-2022-42821: macOS Ventura 13
vendor_apple·2022-10-24·CVSS 5.5
CVE-2022-42821 [MEDIUM] CVE-2022-42821: macOS Ventura 13
Apple Security Update: About the security content of macOS Ventura 13
Product: macOS Ventura
Version: 13
CVE: CVE-2022-42821
Component: BOM
Impact: An app may bypass Gatekeeper checks
Description: A logic issue was addressed with improved checks.
GHSA
GHSA-2675-54p5-24ww: A logic issue was addressed with improved checks
ghsa_unreviewed·2022-12-15
CVE-2022-42821 [MEDIUM] CWE-693 GHSA-2675-54p5-24ww: A logic issue was addressed with improved checks
A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.2, macOS Big Sur 11.7.2, macOS Ventura 13. An app may bypass Gatekeeper checks.
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Microsoft: macOS Sploitlight flaw leaks Apple Intelligence data
blogs_bleepingcomputer·2025-07-28·CVSS 7.1
CVE-2020-9771 [HIGH] Microsoft: macOS Sploitlight flaw leaks Apple Intelligence data
## Microsoft: macOS Sploitlight flaw leaks Apple Intelligence data
## Sergiu Gatlan
Since 2020, Apple has patched other TCC bypasses that exploit Time Machine mounts ( CVE-2020-9771 ), environment variable poisoning ( CVE-2020-9934 ), and a bundle conclusion issue ( CVE-2021-30713 ) . In the past, Microsoft security researchers have also discovered several other TCC bypasses, including powerdir ( CVE-2021-30970 ) and HM-Surf , that could also be abused to gain access to users' private data.
"While similar to prior TCC bypasses like HM-Surf and powerdir, the implications of this vulnerability, which we refer to as 'Sploitlight' for its use of Spotlight plugins, are more severe due to its ability to extract and leak sensitive information cached by Apple Intelligence, such as precise geol
Bleepingcomputer
Microsoft: macOS bug lets hackers install malicious kernel drivers
blogs_bleepingcomputer·2025-01-13·CVSS 5.5
CVE-2024-44243 [MEDIUM] Microsoft: macOS bug lets hackers install malicious kernel drivers
## Microsoft: macOS bug lets hackers install malicious kernel drivers
## Sergiu Gatlan
"System Integrity Protection (SIP) serves as a critical safeguard against malware, attackers, and other cybersecurity threats, establishing a fundamental layer of protection for macOS systems," Microsoft said today in a report that provides more technical details on CVE-2024-44243.
"Bypassing SIP impacts the entire operating system's security and could lead to severe consequences, emphasizing the necessity for comprehensive security solutions that can detect anomalous behavior from specially entitled processes."
Microsoft security researchers have discovered multiple macOS vulnerabilities in recent years. A SIP bypass dubbed 'Shrootless ' ( CVE-2021-30892 ), reported in 2021, also allows attackers to
Checkpoint
26th December – Threat Intelligence Report
blogs_checkpoint·2022-12-26
CVE-2022-41080 26th December – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 26th December – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 26th December, please download our Threat_Intelligence Bulletin
TOP ATTACKS AND BREACHES
LastPass revealed that it has been breached for the second time this year, an event that resulted in attackers stealing customer encrypted password vaults and additional account information. The breach was achieved after attackers used information stolen from the LastPass development environment in the August incident to
http://seclists.org/fulldisclosure/2022/Dec/24http://seclists.org/fulldisclosure/2022/Dec/25https://support.apple.com/en-us/HT213488https://support.apple.com/en-us/HT213533https://support.apple.com/en-us/HT213534http://seclists.org/fulldisclosure/2022/Dec/24http://seclists.org/fulldisclosure/2022/Dec/25https://support.apple.com/en-us/HT213488https://support.apple.com/en-us/HT213533https://support.apple.com/en-us/HT213534
2022-12-15
Published