CVE-2022-22656

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
18/03/2022
Last modified:
02/11/2022

Description

An authentication issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. A local attacker may be able to view the previous logged in user’s desktop from the fast user switching screen.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* 10.15 (including) 10.15.7 (excluding)
cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2022-001:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2022-002:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* 11.6 (including) 11.6.5 (excluding)
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* 12.0 (including) 12.3 (excluding)
cpe:2.3:o:apple:macos:10.15.7:-:*:*:*:*:*:*