CVE-2022-22587
About
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, macOS Big Sur 11.6.3, macOS Monterey 12.2. A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..
Rainforest analyst review
This is a memory-corruption flaw in IOMobileFrameBuffer, a low-level Apple graphics component that lives in the kernel. A malicious application with insufficiently validated input can trigger an out-of-bounds write, corrupting kernel memory in a controlled way and escalating to arbitrary code execution with kernel privileges. That is the highest privilege on the device: once an app breaks into the kernel, the usual sandbox and permission boundaries that separate apps from the system no longer hold.
Apple acknowledged reports that this issue may have been actively exploited in the wild, which puts it in the pattern of iOS and macOS kernel bugs chained by commercial spyware and targeted-intrusion operators, where a browser or app-level bug gets paired with a kernel escalation like this to take full control of a phone. It affects iPhone, iPad, and Mac, so the exposed population is enormous and largely non-technical. The response is simply to install the fixed OS releases (iOS/iPadOS 15.3, macOS 11.6.3 and 12.2); for a bug already used against targets, prompt patching across the fleet is the only meaningful mitigation.
References
Related CVEs
Frequently asked questions
What is CVE-2022-22587?
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, macOS Big Sur 11.6.3, macOS Monterey 12.2. A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..
How severe is CVE-2022-22587?
CVE-2022-22587 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.
How is CVE-2022-22587 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2022-22587?
Public advisories list the following as affected: ipados, iphone os, macos. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2022-22587?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
