PT-2021-7579 · Apple · Apple Macos

Jeremy Brown

·

Published

2021-12-22

·

Updated

2023-06-30

·

CVE-2022-22630

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions macOS versions prior to 11.6.6 macOS versions prior to 12.3 macOS Catalina versions prior to Security Update 2022-004
Description The issue is related to insufficient input validation and a buffer overflow in memory, which can be exploited by a remote attacker to execute arbitrary code or cause a denial of service. A use after free issue was addressed with improved memory management, allowing a remote user to cause an unexpected app termination or arbitrary code execution.
Recommendations For macOS versions prior to 11.6.6, update to macOS Big Sur 11.6.6 to resolve the issue. For macOS versions prior to 12.3, update to macOS Monterey 12.3 to resolve the issue. For macOS Catalina versions prior to Security Update 2022-004, apply Security Update 2022-004 to resolve the issue.

Fix

Buffer Overflow

RCE

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-00121
CVE-2022-22630
ZDI-22-1065

Affected Products

Apple Macos