← Back to browse · API

CVE-2022-22587

Severity
CRITICAL
CVSS
9.8
EPSS
0.11638
Risk score
68.27
CISA KEV
Yes
PoC
No
Published
2022-03-18
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2022-27732, GHSA-P75P-VC6X-P9WF
Products
Apple:iOS and iPadOS unspecified <15.3, Apple:iOS and macOS, Apple:macOS unspecified <11.6, Apple:macOS unspecified <12.2
Sources
cisa.gov CVE-2022-22587
euvd EUVD-2022-27732

Description

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, macOS Big Sur 11.6.3, macOS Monterey 12.2. A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..

References