SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Apple Addressed High Severity Flaws in macOS, iOS – Patch Now

Apple Addressed High Severity Flaws in macOS, iOS – Patch Now

Apple April 2022 Security Update, two high severity zero-day flaws tracked as “CVE-2022-22674” and “CVE-2022-22675” have been reported in Apple macOS and iOS. Apple has released patches for these two zero-day CVEs affecting macOS and iOS. A critical vulnerability is, therefore, present in Apple macO...

Apr 3, 2022By Mansij Gupta2 min read

Apple April 2022 Security Update, two high severity zero-day flaws tracked as “CVE-2022-22674” and “CVE-2022-22675” have been reported in Apple macOS and iOS. Apple has released patches for these two zero-day CVEs affecting macOS and iOS. A critical vulnerability is, therefore, present in Apple macOS and iOS up to 15.4.0 (Smartphone Operating System). You can detect and remediate these vulnerabilities with an effective vulnerability management tool and patch management tool.

“Apple is aware of a report that this issue may have been in active exploitation.” Moreover, It refers to what it describes as an “Out of bounds read and write” flaw. An anonymous researcher is identifying the flaw.

Apple fixes high severity vulnerability 2022 Zero days CVEs

Apple fixes high severity vulnerability 2022; these CVEs are Apple’s fourth and fifth zero-day vulnerabilities this year. In January 2022,  Apple patched two zero-day flaws that involved code execution flaws—also issued one patch for high severity WebKit flaw that allows an attacker to use malicious web content to finally execute malicious code.

Affected Products: macOS, iOS

Affected version: macOS, iOS up to 15.4.0

CVE: CVE-2022-22674

Available for: macOS Monterey

Description: An out-of-bounds read issue in Intel Graphic Driver may lead to the disclosure of kernel memory and be with improving input validation, which can be active exploitation.

Impact: Successful exploitation may allow attackers to read kernel memory. However, the manipulation with an unknown input may lead to memory corruption vulnerability.

Severity: High

Apple fixes high severity vulnerability 2022

CVE: CVE-2022-22675

Available for: macOS Monterey

Description: An out-of-bounds write issue was addressed with improved bounds checking. This issue affects an unknown code of the component AppleAVD.

Impact: Successful exploitation may allow attackers to therefore execute arbitrary code with kernel privileges.

Severity: High

SanerNow VM and SanerNow PM detect these vulnerabilities and therefore, automatically fix them using security updates. Use SanerNow and keep your systems updated and secure.

Featured Posts

Open Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras
Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

CVE Research

Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

A single operator compromised 14,530+ Dahua cameras across Ukraine and Russia in 35 days, chaining credential brute-force, a CVE-2021-33044/33045 authentication bypass, and P2P relay abuse to plant a persistent backdoor and harvest transferable admin access.

Aug 21, 2026

Open Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF
Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE Research

Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE-2026-19478 is a critical code injection vulnerability in GitLab CE/EE that allows an unauthenticated attacker to modify or delete public projects and user data by abusing a GraphQL directive. A second high-severity issue, CVE-2026-19650, involves cross-site request forgery in the GraphQL multiplex query handler. This article examines how the critical vulnerability works, the availability of a public proof-of-concept, the potential impact on self-managed instances, the affected versions, and the security updates released to remediate both issues.

Aug 19, 2026

Open No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners
No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

CVE Research

No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

Aug 19, 2026

Open Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies
Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

CVE Research

Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

Aug 19, 2026

Apple Addressed High Severity Flaws in macOS, iOS – Patch Now | SecPod