News

Apple Releases macOS Monterey 12.2 to Public – Fixes Safari Privacy Vulnerability

Apple on Wednesday released macOS Monterey 12.2 to the public. The release is the second major update to macOS Monterey, which was launched in October 2021. The update comes a bit over a month after the release of macOS Monterey 12.1.

The macOS Monterey 12.2 update can be downloaded to a compatible Mac via the Software Update section of System Preferences. Like all Mac updates, ‌the macOS Monterey 12.2 update is available free of charge. The update is also available in the Mac App Store.

A full list of security fixes that are in the update from Apple’s security update support document:

Security Update 2022-001 Catalina

Released January 26, 2022

Kernel

Available for: macOS Catalina

Impact: A malicious application may be able to execute arbitrary code with kernel privileges

Description: A buffer overflow issue was addressed with improved memory handling.

CVE-2022-22593: Peter Nguyễn Vũ Hoàng of STAR Labs

Model I/O

Available for: macOS Catalina

Impact: Processing a maliciously crafted STL file may lead to unexpected application termination or arbitrary code execution

Description: An information disclosure issue was addressed with improved state management.

CVE-2022-22579: Mickey Jin (@patch1t) of Trend Micro

PackageKit

Available for: macOS Catalina

Impact: An application may be able to access restricted files

Description: A permissions issue was addressed with improved validation.

CVE-2022-22583: an anonymous researcher, Ron Hass (@ronhass7) of Perception Point, Mickey Jin (@patch1t)

Sandbox

Available for: macOS Catalina

Impact: A malicious application may be able to bypass certain Privacy preferences

Description: A logic issue was addressed with improved restrictions.

CVE-2021-30946: an anonymous researcher, @gorelics

TCC

Available for: macOS Catalina

Impact: A malicious application may be able to bypass certain Privacy preferences

Description: This issue was addressed with improved checks.

CVE-2021-30972: Xuxiang Yang (@another1024), Zhipeng Huo (@R3dF09), and Yuebin Sun (@yuebinsun2020) of Tencent Security Xuanwu Lab (xlab.tencent.com), Wojciech Reguła (@_r3ggi), jhftss (@patch1t), Csaba Fitzl (@theevilbit) of Offensive Security

Apple has also released a macOS Big Sur 11.6.3 update for those still running macOS Big Sur and macOS Catalina Security Update 2022-001 for those still on Catalina.

Chris Hauk

Chris is a Senior Editor at Mactrast. He lives somewhere in the deep Southern part of America, and yes, he has to pump in both sunshine and the Internet.