SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Apple Addressed High Severity Flaws in macOS, iOS – Patch Now

Apple Addressed High Severity Flaws in macOS, iOS – Patch Now

Apple April 2022 Security Update, two high severity zero-day flaws tracked as “CVE-2022-22674” and “CVE-2022-22675” have been reported in Apple macOS and iOS. Apple has released patches for these two zero-day CVEs affecting macOS and iOS. A critical vulnerability is, therefore, present in Apple macO...

Apr 3, 2022By Mansij Gupta2 min read

Apple April 2022 Security Update, two high severity zero-day flaws tracked as “CVE-2022-22674” and “CVE-2022-22675” have been reported in Apple macOS and iOS. Apple has released patches for these two zero-day CVEs affecting macOS and iOS. A critical vulnerability is, therefore, present in Apple macOS and iOS up to 15.4.0 (Smartphone Operating System). You can detect and remediate these vulnerabilities with an effective vulnerability management tool and patch management tool.

“Apple is aware of a report that this issue may have been in active exploitation.” Moreover, It refers to what it describes as an “Out of bounds read and write” flaw. An anonymous researcher is identifying the flaw.

Apple fixes high severity vulnerability 2022 Zero days CVEs

Apple fixes high severity vulnerability 2022; these CVEs are Apple’s fourth and fifth zero-day vulnerabilities this year. In January 2022,  Apple patched two zero-day flaws that involved code execution flaws—also issued one patch for high severity WebKit flaw that allows an attacker to use malicious web content to finally execute malicious code.

Affected Products: macOS, iOS

Affected version: macOS, iOS up to 15.4.0

CVE: CVE-2022-22674

Available for: macOS Monterey

Description: An out-of-bounds read issue in Intel Graphic Driver may lead to the disclosure of kernel memory and be with improving input validation, which can be active exploitation.

Impact: Successful exploitation may allow attackers to read kernel memory. However, the manipulation with an unknown input may lead to memory corruption vulnerability.

Severity: High

Apple fixes high severity vulnerability 2022

CVE: CVE-2022-22675

Available for: macOS Monterey

Description: An out-of-bounds write issue was addressed with improved bounds checking. This issue affects an unknown code of the component AppleAVD.

Impact: Successful exploitation may allow attackers to therefore execute arbitrary code with kernel privileges.

Severity: High

SanerNow VM and SanerNow PM detect these vulnerabilities and therefore, automatically fix them using security updates. Use SanerNow and keep your systems updated and secure.

Featured Posts

Open WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels
WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

CVE Research

WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

Oct 1, 2026

Open OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure
OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

CVE Research

OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

Two critical vulnerabilities added to CISA KEV on September 24, 2026 reveal sharply different exploitation timelines. CVE-2026-71362 saw publicly documented exploitation roughly one day after Adobe's patch release, while CVE-2026-5430 had a 133-day vendor-remediation-to-observed-exploitation interval.

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026
Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

CVE Research

Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

Three Linux kernel vulnerabilities entered CISA’s KEV catalog on September 18, 2026, although their Linux 6.12 fixes were available 91–386 days earlier. This analysis separates patch availability, CVE publication, and known-exploitation status without treating KEV dates as first-attack dates.

Sep 28, 2026