Apple Security Advisories · January 2022 — Apple Security Advisories
28 advisories 28 CVEs 11 EXPLOITED

Apple-vendor CVEs for 2022-01. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 11 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2022-22587

iPadOSExploitedCISA KEV listedHIGH2022-01-26

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, macOS Big Sur 11.6.3, macOS Monterey 12.2. A malicious application may be able to execute arbitrary code with kernel privileges. Ap...

CVEs:CVE-2022-22587

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2022-22586

macOSExploitedCISA KEV listedHIGH2022-01-26

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.2. A malicious application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2022-22586

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-22579

iPadOSExploitedCISA KEV listedHIGH2022-01-26

An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 15.3 and iPadOS 15.3, tvOS 15.3, Security Update 2022-001 Catalina, macOS Monterey 12.2, macOS Big Sur 11.6.3. Processing a maliciously crafted STL...

CVEs:CVE-2022-22579

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
mac_os_x affected apple
tvos affected apple
Upstream advisory

CVE-2022-22583

macOSExploitedCISA KEV listedMEDIUM2022-01-26

A permissions issue was addressed with improved validation. This issue is fixed in Security Update 2022-001 Catalina, macOS Monterey 12.2, macOS Big Sur 11.6.3. An application may be able to access restricted files.

CVEs:CVE-2022-22583

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
mac_os_x affected apple
Upstream advisory

CVE-2022-22585

iPadOSExploitedCISA KEV listedHIGH2022-01-26

An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, macOS Monterey 12.2, macOS Big Sur 11.6.3. An application...

CVEs:CVE-2022-22585

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2022-22584

iPadOSExploitedCISA KEV listedCRITICAL2022-01-26

A memory corruption issue was addressed with improved validation. This issue is fixed in tvOS 15.3, iOS 15.3 and iPadOS 15.3, watchOS 8.4, macOS Monterey 12.2. Processing a maliciously crafted file may lead to arbitrary code execution.

CVEs:CVE-2022-22584

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2022-22590

iPadOSExploitedCISA KEV listedCRITICAL2022-01-26

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing maliciously crafted web content may lead to arbitrary code execu...

CVEs:CVE-2022-22590

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2022-22592

iPadOSExploitedCISA KEV listedCRITICAL2022-01-26

A logic issue was addressed with improved state management. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing maliciously crafted web content may prevent Content Security Policy from b...

CVEs:CVE-2022-22592

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone affected apple
macos affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2022-22593

iPadOSExploitedCISA KEV listedHIGH2022-01-26

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Security Update 2022-001 Catalina, macOS Monterey 12.2, macOS Big Sur 11.6.3. A malicious application may be a...

CVEs:CVE-2022-22593

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2022-22591

macOSExploitedCISA KEV listedHIGH2022-01-26

A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.2. A malicious application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2022-22591

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-22578

iPadOSExploitedCISA KEV listedHIGH2022-01-26

A logic issue was addressed with improved validation. This issue is fixed in tvOS 15.3, iOS 15.3 and iPadOS 15.3, watchOS 8.4, macOS Monterey 12.2. A malicious application may be able to gain root privileges.

CVEs:CVE-2022-22578

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2022-0318

OtherPoC exploitCRITICAL2022-01-21

Heap-based Buffer Overflow in vim/vim prior to 8.2.

CVEs:CVE-2022-0318

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-22589

iPadOSPoC exploitMEDIUM2022-01-26

A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing a maliciously crafted mail message may lead to running arbitrary ja...

CVEs:CVE-2022-22589

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
mac_os_x affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2022-0128

OtherPoC exploitHIGH2022-01-06

vim is vulnerable to Out-of-bounds Read

CVEs:CVE-2022-0128

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
mac_os_x affected apple
Upstream advisory

CVE-2022-0158

OtherPoC exploitCRITICAL2022-01-10

vim is vulnerable to Heap-based Buffer Overflow

CVEs:CVE-2022-0158

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-0261

OtherPoC exploitCRITICAL2022-01-18

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

CVEs:CVE-2022-0261

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
mac_os_x affected apple
Upstream advisory

CVE-2022-0361

OtherPoC exploitCRITICAL2022-01-26

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

CVEs:CVE-2022-0361

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-0368

OtherPoC exploitHIGH2022-01-26

Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

CVEs:CVE-2022-0368

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-0392

OtherPoC exploitCRITICAL2022-01-28

Heap-based Buffer Overflow in GitHub repository vim prior to 8.2.

CVEs:CVE-2022-0392

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-21658

OtherPoC exploitHIGH2022-01-16

Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, especially safe concurrency. The Rust Security Response WG was notified that the `std::fs::remove_dir_all` standard library function is vulnerable a rac...

CVEs:CVE-2022-21658

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2022-0359

OtherPoC exploitCRITICAL2022-01-26

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

CVEs:CVE-2022-0359

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-22594

iPadOSPoC exploitMEDIUM2022-01-26

A cross-origin issue in the IndexDB API was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. A website may be able to track sensitive user information.

CVEs:CVE-2022-22594

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2022-22676

macOSPoC exploitMEDIUM2022-01-26

An event handler validation issue in the XPC Services API was addressed by removing the service. This issue is fixed in macOS Monterey 12.2. An application may be able to delete files for which it does not have permission.

CVEs:CVE-2022-22676

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-0351

OtherPoC exploitHIGH2022-01-25

Access of Memory Location Before Start of Buffer in GitHub repository vim/vim prior to 8.2.

CVEs:CVE-2022-0351

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-22646

macOSPoC exploitMEDIUM2022-01-26

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Monterey 12.2. A malicious application may be able to modify protected parts of the file system.

CVEs:CVE-2022-22646

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-22588

iPadOSCoalition ESS < 30%CRITICAL2022-01-13

A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 15.2.1 and iPadOS 15.2.1. Processing a maliciously crafted HomeKit accessory name may cause a denial of service.

CVEs:CVE-2022-22588

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.