CVE-2022-42864Race Condition in Apple Macos

CWE-362Race Condition10 documents4 sources
Severity
7.0HIGHNVD
EPSS
4.0%
top 11.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 15

Description

A race condition was addressed with improved state handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages15 packages

Appleapple/macos_monterey12.6.2
CVEListV5apple/macosunspecified11.7
NVDapple/macos12.012.6.2+2
Appleapple/macos_big_sur11.7.2

🔴Vulnerability Details

2
GHSA
GHSA-g6qw-hmvp-hf86: A race condition was addressed with improved state handling2022-12-15
VulnCheck
Apple ipados Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')2022

📋Vendor Advisories

7
Apple
CVE-2022-42864: iOS 16.2 and iPadOS 16.22022-12-13
Apple
CVE-2022-42864: iOS 15.7.2 and iPadOS 15.7.22022-12-13
Apple
CVE-2022-42864: macOS Big Sur 11.7.22022-12-13
Apple
CVE-2022-42864: tvOS16.22022-12-13
Apple
CVE-2022-42864: watchOS 9.22022-12-13