LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-22674: Apple macOS Out-of-Bounds Read Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 4, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 25, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-22674 to its Known Exploited Vulnerabilities catalog on Apr 4, 2022, with a federal patch deadline of Apr 25, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory.

CVE-2022-22674 is an out-of-bounds read vulnerability in Apple macOS that can allow a malicious application to read kernel memory. It matters because kernel memory often holds sensitive system state; unauthorized reads can aid further compromise, privilege escalation, or information theft on affected Macs. Public detail is limited to the CISA summary that macOS Monterey is impacted; teams should treat any unpatched Monterey systems as in scope until the vendor advisory is checked.

How it works

The weakness is classified under CWE-125 (out-of-bounds read) and CWE-20 (improper input validation). In this class of flaw, software fails to properly validate bounds or input before reading memory. An attacker who can run an application on the system may craft input or trigger a code path that causes the kernel (or a kernel-facing component) to read past the end of an intended buffer. The result is disclosure of adjacent kernel memory contents to the unprivileged application. Exact trigger conditions, components, and exploitation mechanics are not detailed in the provided facts; confirm those against the Apple security advisory for this CVE.

Am I affected? How to find it in your systems

This vulnerability affects Apple macOS, specifically called out for Monterey in the CISA summary. macOS commonly runs on Mac desktops, laptops, and some servers or virtual machines in enterprise environments.

How to remediate

Patch first. Apply the macOS security updates that Apple issued for this vulnerability, following the vendor instructions referenced by CISA. Use your standard update channels (Software Update, MDM-enforced policies, or Apple Business Manager workflows) and verify installation of the fixed build on every managed Mac.

If you can't patch immediately

Compensating controls reduce but do not eliminate risk until the vendor update is applied.

If your data may have been exposed

Actively exploited vulnerabilities can lead to broader compromise and data exposure even when ransomware use is not documented for this CVE. If you suspect systems were vulnerable and reachable by untrusted applications, treat the incident as a potential breach: isolate hosts, preserve logs, and follow your incident-response process. You can run a free exposure scan of your email addresses against known breach data to check whether credentials or personal information have already appeared in public dumps, then force password resets and enable multi-factor authentication where relevant.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApple · macOS
WeaknessCWE-20
Added to CISA KEVApr 4, 2022
Federal patch deadlineApr 25, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities