CVE-2022-22675

HIGH(7.8)KEVElevated Risk

Apple macOS Out-of-Bounds Write Vulnerability

Description

CVE-2022-22675 is an out-of-bounds write vulnerability in Apple's AppleAVD media processing component on macOS Monterey that allows an application to execute arbitrary code with kernel privileges. This vulnerability was actively exploited as a zero-day before Apple released patches. It was added to CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation. The EPSS score of 0.2% (58th percentile) reflects limited but targeted exploitation activity typical of Apple zero-day vulnerabilities.

KEV Information

Vendor
Apple
Product
macOS
Date Added
April 4, 2022
Due Date
April 25, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
appleipados< 15.4.1
appleiphone os< 15.4.1
applemacos>= 11.0, < 11.6.6; >= 12.0.0, < 12.3.1
appletvos< 15.5
applewatchos< 8.6

Multiple CVSS Assessments

Source: [email protected](Primary)
7.8
HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
7.8
HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-787: Out-of-bounds Write

An out-of-bounds write occurs when a program writes data past the end or before the beginning of a buffer, potentially leading to memory corruption, code execution, or system crashes. In CVE-2022-22675, the AppleAVD component fails to properly validate bounds during media processing, allowing kernel-level code execution. For more details, see CWE-787.

Impact Analysis

Successful exploitation of this vulnerability grants an attacker kernel-level code execution on affected macOS systems, representing the highest level of system compromise. Kernel privilege access allows complete control over the operating system, including the ability to install persistent backdoors, bypass all security mechanisms including sandboxing and System Integrity Protection, access all user data, and monitor system activity. The media processing attack vector means that exploitation could potentially be triggered through malicious media content, making targeted attacks against specific individuals or organizations feasible through crafted media files.

Exploit Maturity

CVE-2022-22675 was actively exploited as a zero-day vulnerability before Apple's patch release and was added to CISA's KEV catalog on April 4, 2022. Apple acknowledged the zero-day exploitation in its security advisory. The relatively low EPSS score of 0.2% (58th percentile) is consistent with Apple zero-day exploitation patterns, where exploits are typically used in highly targeted operations by sophisticated threat actors rather than in mass exploitation campaigns. The targeted nature and kernel-level impact suggest possible use in surveillance operations.

Remediation

  1. Update macOS Monterey to version 12.3.1 or later, which addresses the AppleAVD vulnerability, as required by CISA's KEV catalog.
  2. Enable automatic macOS security updates to ensure timely application of future patches.
  3. Implement endpoint detection and response (EDR) solutions capable of monitoring for kernel-level exploitation attempts on macOS systems.
  4. Review macOS systems for indicators of compromise, particularly unusual kernel extension activity or unexpected processes with elevated privileges.
  5. Apply the principle of least privilege by restricting administrative access and ensuring users operate with standard accounts for daily tasks.

Technical Details

The vulnerability exists in AppleAVD, the hardware-accelerated video decoder component in macOS that processes media content at the kernel level. During the processing of certain media streams, AppleAVD fails to properly validate the size of data being written to an internal buffer, allowing an attacker to write data beyond the buffer's boundaries. This out-of-bounds write can corrupt adjacent kernel memory, which can be leveraged to achieve arbitrary code execution with kernel privileges. The vulnerability can be triggered by processing maliciously crafted media content, meaning an attacker could potentially exploit it through media files delivered via web pages, messages, or other content delivery mechanisms.

Frequently Asked Questions

What is CVE-2022-22675?

CVE-2022-22675 is an out-of-bounds write vulnerability in Apple's AppleAVD component on macOS Monterey. It allows attackers to execute arbitrary code with kernel privileges by exploiting improper bounds checking during media processing. Apple confirmed it was actively exploited as a zero-day.

Which Apple products are affected?

The vulnerability specifically affects macOS Monterey systems prior to version 12.3.1. The AppleAVD component is the hardware-accelerated video decoder used for media processing on Apple silicon and Intel-based Macs.

Was this used in targeted attacks?

Yes, Apple confirmed that the vulnerability was actively exploited before the patch was available. The exploitation pattern is consistent with targeted attacks by sophisticated threat actors, which is typical for Apple zero-day vulnerabilities.

How can I verify my system is patched?

Check your macOS version by clicking the Apple menu and selecting "About This Mac." Ensure you are running macOS Monterey 12.3.1 or later. Enable automatic updates to receive future security patches promptly.

CVSS Score

7.8
HIGH(7.8)

EPSS Score

EPSS Score12.49%
EPSS Percentile95.9%

Dates

PublishedMay 26, 2022
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.