CVE-2022-26722
Description
A memory initialization issue was addressed. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application may be able to gain root privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A memory initialization issue in macOS allows a malicious application to gain root privileges. Fixed in macOS Monterey 12.4, Big Sur 11.6.6, and Security Update 2022-004 Catalina.
Vulnerability
CVE-2022-26722 is a memory initialization issue in macOS that may allow a malicious application to gain root privileges. The vulnerability exists in unspecified system components and was addressed in macOS Monterey 12.4 [1], macOS Big Sur 11.6.6 [2], and Security Update 2022-004 Catalina [3]. The issue stems from improper memory initialization, which can be leveraged to corrupt kernel memory and escalate privileges.
Exploitation
Exploitation requires a malicious application running on the local system. The attacker does not need elevated privileges initially; a standard user-level application can trigger the vulnerability. The exact exploitation steps are not disclosed by Apple, but the flaw can be triggered by a crafted application that exploits the memory initialization issue to achieve code execution with root privileges.
Impact
Successful exploitation allows an attacker to execute arbitrary code with kernel privileges, effectively gaining full control over the affected macOS system. The impact is complete compromise of confidentiality, integrity, and availability.
Mitigation
Apple released fixes on May 16, 2022, in macOS Monterey 12.4 [1], macOS Big Sur 11.6.6 [2], and Security Update 2022-004 Catalina [3]. Users should update to the patched versions immediately. No workarounds are provided by Apple. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog as of this writing.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
5- Range: <11.6.6
- Range: <12.4
- Range: unspecified
- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- support.apple.com/en-us/HT213255mitrex_refsource_MISC
- support.apple.com/en-us/HT213256mitrex_refsource_MISC
- support.apple.com/en-us/HT213257mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.