LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-22675: Apple macOS Out-of-Bounds Write Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 4, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 25, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-22675 to its Known Exploited Vulnerabilities catalog on Apr 4, 2022, with a federal patch deadline of Apr 25, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges.

CVE-2022-22675 is an out-of-bounds write vulnerability in Apple macOS that can let a malicious application run arbitrary code with kernel privileges. CISA notes it affects macOS Monterey and can elevate an app to the highest privilege level on the system, which makes containment and rapid patching essential for any environment that runs Mac endpoints.

Because kernel-level code execution undermines process isolation, disk encryption protections, and endpoint controls, IT and security teams should treat this as a high-priority local privilege-escalation risk and confirm exact impact against Apple’s advisory.

How it works

The flaw is classified under CWE-20 (improper input validation) and CWE-125 (out-of-bounds read), and is described as an out-of-bounds write condition. In practical terms, the operating system fails to properly validate or bound-check data supplied by an application before writing it into kernel memory. An attacker who can run code in user space—typically via a malicious or compromised application—can trigger the write past the intended buffer boundary. That corruption can be leveraged to alter kernel structures or control flow, resulting in arbitrary code execution with kernel privileges.

No public exploit mechanics beyond this class description are provided here; defenders should rely on the vendor advisory for any additional technical detail rather than assuming specific trigger paths or primitives.

Am I affected? How to find it in your systems

The vulnerability is reported against Apple macOS, specifically called out for macOS Monterey in the CISA summary. It can appear on any Mac that has not received the corresponding security update—laptops, desktops, and any managed or BYOD devices running the affected release train.

How to remediate

Patch first. Apply the macOS security update that Apple released to address CVE-2022-22675, following the vendor’s instructions exactly. CISA’s required action is simply to apply updates per vendor instructions.

If you can't patch immediately

When immediate patching is blocked by testing or operational constraints, reduce the attack surface until the update can be applied.

If your data may have been exposed

Actively exploited kernel vulnerabilities can lead to full system compromise and subsequent data theft, even when ransomware use has not been documented for this CVE. If you suspect exposure, isolate the affected Mac, preserve forensic evidence, rotate credentials that may have been present on the device, and review network logs for follow-on activity. You can also run a free exposure scan of your email addresses against known breach data to determine whether associated credentials have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApple · macOS
WeaknessCWE-20
Added to CISA KEVApr 4, 2022
Federal patch deadlineApr 25, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities