Impact
A malicious application can cause unintended changes to memory that is shared between processes, a classic memory corruption flaw. Such corruption can potentially alter the state of cooperating processes, leading to data corruption, privilege escalation, or even arbitrary code execution if a process depends on the corrupted data. The vulnerability arises from inadequate state management and presents an integrity risk for all processes sharing the affected memory region.
Affected Systems
The flaw affects Apple macOS Monterey prior to version 12.4. The vulnerability is addressed in macOS Monterey 12.4, so any installation of Monterey 12.0‑12.3 is potentially vulnerable.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in CISA KEV, so the known exploitation probability is unclear. However, an attacker with the ability to run a malicious application on a system could exploit this flaw locally, potentially gaining control over the affected processes. With no public exploit actively in use and without a KEV designation, the risk is considered moderate, but the severe impact of memory corruption warrants prompt remediation.
OpenCVE Enrichment