← Back to browse · API

CVE-2022-22675

Severity
HIGH
CVSS
7.8
EPSS
0.12642
Risk score
60.62
CISA KEV
Yes
PoC
No
Published
2022-05-26
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2022-27820, GHSA-XJ88-RF28-XGV9
Products
Apple:iOS and iPadOS unspecified <15.4, Apple:macOS, Apple:macOS unspecified <12.3, Apple:watchOS unspecified <11.6, Apple:watchOS unspecified <15.5, Apple:watchOS unspecified <8.6
Sources
cisa.gov CVE-2022-22675
euvd EUVD-2022-27820

Description

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.3.1, iOS 15.4.1 and iPadOS 15.4.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..

References