EXPOSURES › CVE-2022-22587
CVE-2022-22587
HIGH ⌖ ON CISA KEV · EXPLOITEDA memory corruption flaw in Apple's IOMobileFrameBuffer allowed malicious apps to execute kernel-level code, and it was actively exploited in the wild.
This vulnerability enabled arbitrary kernel code execution from a malicious application, representing a severe breach of the device's security model. For DIB organizations, reliance on unpatched Apple devices in classified environments risks total system compromise and violates CMMC/NIST 800-171 requirements for patching known vulnerabilities. Organizations must enforce strict device management and rapid patching cycles to prevent exploitation of such high-severity flaws.
Shame score — The vulnerability was actively exploited in the wild (KEV) and allowed arbitrary kernel code execution, indicating a severe, avoidable failure in Apple's security engineering and patching cadence.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apple IOMobileFrameBuffer contains a memory corruption vulnerability which can allow a malicious application to execute arbitrary code with kernel privileges.