← Back to CVE List
Vulnerability Intelligence Report
Apple macOS Out-of-Bounds Read Vulnerability

CVE-2022-22674

An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Monterey 12.3.1, Security Update 2022-004 Catalina, macOS Big Sur 11.6.6. A local user may be able to read kernel memory.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
5.5
MEDIUM
Exploitability:1.9
Impact Score:3.6
EPSS Probability:1.13%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-125 ↗CWE-125 Out-of-bounds Read

Affected Products & Versions

Vendor Product Affected Versions
Apple macOS unspecified < 12.3 (affected)
Apple macOS unspecified < 2022 (affected)
Apple macOS unspecified < 11.6 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
1.132%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityApple Inc. · Vendor · USA
Reserved2022-01-05T00:00:00
Published2022-05-26T17:43:37
Last Updated2025-10-21T23:15:39

LINK COPIED TO CLIPBOARD