CVE-2022-22650 is a local privilege escalation vulnerability affecting Apple macOS Big Sur and Monterey, where a malicious plug-in could inherit an application's permissions to access sensitive user data. With a CVSS score of 5.5 (Medium), it requires local access and low privileges, but could lead to high confidentiality impact. Apple addressed this issue with improved checks in macOS Big Sur 11.6.5, macOS Monterey 12.3, and Security Update 2022-003 Catalina. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.15, < 10.15.7CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
10.15.7CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2022-001:*:*:*:*:*:* | ||
10.15.7CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2022-002:*:*:*:*:*:* | ||
>= 11.6, < 11.6.5CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
>= 12.0, < 12.3CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.