CVE-2022-22657 is a memory initialization vulnerability affecting Apple Logic Pro, GarageBand, and macOS Monterey. This flaw, rated High severity (CVSS 7.8), could allow an attacker to achieve arbitrary code execution or cause application termination by tricking a user into opening a specially crafted file. While no public exploits, Metasploit modules, or active exploitation have been observed, and community discussion is minimal, the potential for significant impact necessitates patching. Apple has addressed this issue in Logic Pro 10.7.3, GarageBand 10.4.6, and macOS Monterey 12.3.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.4.6CPE matchmatch criteria | cpe:2.3:a:apple:garageband:*:*:*:*:*:*:*:* | ||
< 10.7.3CPE matchmatch criteria | cpe:2.3:a:apple:logic_pro_x:*:*:*:*:*:*:*:* | ||
< 12.3CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
< 10.4CPE match | cpe:2.3:a:apple:macos:*:*:*:*:*:*:*:* | ||
< 10.7CPE match | cpe:2.3:a:apple:macos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.