LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-22587: Apple Memory Corruption Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jan 28, 2022
CVSS 9.8 · Critical⚠ Actively exploited (CISA KEV)
9.8
CVSS score
Critical
Severity
Active
CISA KEV
No
Ransomware use
Feb 11, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-22587 to its Known Exploited Vulnerabilities catalog on Jan 28, 2022, with a federal patch deadline of Feb 11, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, macOS Big Sur 11.6.3, macOS Monterey 12.2. A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..

CVE-2022-22587 is a memory corruption vulnerability in Apple’s IOMobileFrameBuffer component on iOS and macOS. A malicious application can abuse it to run arbitrary code with kernel privileges, giving an attacker deep control over the device. That level of access matters because kernel compromise can bypass many user-space protections and lead to full device takeover.

Public detail is limited to the CISA description and the associated weakness classes; exact affected builds, exploit mechanics, and scoring must be confirmed against the vendor advisory. CISA’s required action is to apply updates per Apple’s instructions. Ransomware use is not documented for this CVE.

How it works

The flaw is classified under CWE-20 (Improper Input Validation) and CWE-787 (Out-of-bounds Write). IOMobileFrameBuffer handles frame-buffer related operations; insufficient validation of input supplied by an application can corrupt memory structures that the kernel relies on.

In practice, an attacker who can run a malicious application on the device crafts input that triggers the out-of-bounds write. Successful corruption can redirect control flow or overwrite critical kernel data, resulting in arbitrary code execution at kernel privilege. No public exploit code or step-by-step mechanics are provided in the given facts; defenders should treat any untrusted application that can reach the vulnerable component as a potential vector and verify technical details only from Apple’s advisory.

Am I affected? How to find it in your systems

The vulnerability affects Apple iOS and macOS systems that include the IOMobileFrameBuffer component. These platforms are common on corporate and personally owned iPhones, iPads, and Macs managed by IT.

How to remediate

Patch first. Apply the updates Apple released for this vulnerability exactly as described in the vendor advisory. CISA explicitly directs organizations to apply updates per vendor instructions.

If you can't patch immediately

When immediate patching is blocked by testing or operational constraints, reduce exposure with compensating controls while you prepare the update.

These steps lower risk but do not eliminate it; schedule the official Apple update as the primary remediation.

If your data may have been exposed

Actively exploited kernel-level vulnerabilities can lead to full device compromise and subsequent data theft or further lateral movement. If you suspect exploitation, isolate affected devices, preserve forensic evidence, and follow your incident-response plan. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether credentials or personal information have already appeared in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApple · iOS and macOS
WeaknessCWE-787
CVSS base score9.8 (Critical)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
PublishedMar 18, 2022
Added to CISA KEVJan 28, 2022
Federal patch deadlineFeb 11, 2022
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities