Apple Security Advisories · February 2022 — Apple Security Advisories
14 advisories 14 CVEs 1 EXPLOITED

Apple-vendor CVEs for 2022-02. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2022-22620

iPadOSExploitedCISA KEV listedCRITICAL2022-02-11

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to a...

CVEs:CVE-2022-22620

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
Upstream advisory

CVE-2022-0572

OtherPoC exploitCRITICAL2022-02-14

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

CVEs:CVE-2022-0572

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-0714

OtherPoC exploitCRITICAL2022-02-22

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4436.

CVEs:CVE-2022-0714

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-23308

OtherPoC exploitCRITICAL2022-02-22

valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.

CVEs:CVE-2022-23308

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2022-0530

OtherPoC exploitCRITICAL2022-02-09

A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code exec...

CVEs:CVE-2022-0530

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
mac_os_x affected apple
Upstream advisory

CVE-2021-45444

OtherPoC exploitCRITICAL2022-02-14

In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.

CVEs:CVE-2021-45444

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
mac_os_x affected apple
Upstream advisory

CVE-2022-0629

OtherPoC exploitCRITICAL2022-02-16

Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

CVEs:CVE-2022-0629

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-0685

OtherPoC exploitHIGH2022-02-20

Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418.

CVEs:CVE-2022-0685

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-0729

OtherPoC exploitHIGH2022-02-23

Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440.

CVEs:CVE-2022-0729

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-0554

OtherPoC exploitHIGH2022-02-09

Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.

CVEs:CVE-2022-0554

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-0696

OtherPoC exploitMEDIUM2022-02-21

NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428.

CVEs:CVE-2022-0696

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-24666

OtherCoalition ESS < 30%CRITICAL2022-02-09

A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a specially crafted HTTP/2 frame. This attack affects all swift-nio-http2 versions from 1.0.0 to 1.19.1. This vulnerability is caused by a log...

CVEs:CVE-2022-24666

Affected products

ProductStatusVendorPackageEcosystem
swiftnio_http\/2 affected apple
Upstream advisory

CVE-2022-24667

OtherCoalition ESS < 30%CRITICAL2022-02-09

A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a specially crafted HPACK-encoded header block. This attack affects all swift-nio-http2 versions from 1.0.0 to 1.19.1. There are a number of i...

CVEs:CVE-2022-24667

Affected products

ProductStatusVendorPackageEcosystem
swiftnio_http\/2 affected apple
Upstream advisory

CVE-2022-24668

OtherCoalition ESS < 30%CRITICAL2022-02-09

A program using swift-nio-http2 is vulnerable to a denial of service attack caused by a network peer sending ALTSVC or ORIGIN frames. This attack affects all swift-nio-http2 versions from 1.0.0 to 1.19.1. This vulnerability is caused by a logical error...

CVEs:CVE-2022-24668

Affected products

ProductStatusVendorPackageEcosystem
swiftnio_http\/2 affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.