CVE-2022-46689

HIGH EXPLOITED

macOS Dirty Cow Arbitrary File Write Local Privilege Escalation

Title source: metasploit

Description

A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.

Exploits (21)

nomisec WORKING POC 889 stars
by ginsudev · poc
https://github.com/ginsudev/WDBFontOverwrite
nomisec WORKING POC 411 stars
by zhuowei · local
https://github.com/zhuowei/MacDirtyCowDemo
nomisec WORKING POC 150 stars
by straight-tamago · poc
https://github.com/straight-tamago/FileSwitcherX
nomisec WORKING POC 129 stars
by straight-tamago · poc
https://github.com/straight-tamago/NoCameraSound
nomisec WORKING POC 81 stars
by mineek · poc
https://github.com/mineek/FileManager
nomisec WORKING POC 73 stars
by straight-tamago · poc
https://github.com/straight-tamago/NoHomeBar
nomisec WORKING POC 57 stars
by straight-tamago · poc
https://github.com/straight-tamago/DockTransparent
nomisec WORKING POC 23 stars
by bomberfish · poc
https://github.com/bomberfish/Mandela-Legacy
nomisec WORKING POC 20 stars
by bomberfish · poc
https://github.com/bomberfish/Mandela-Classic
nomisec WORKING POC 13 stars
by enty8080 · local
https://github.com/enty8080/MacDirtyCow
nomisec NO CODE 1 stars
by tdquang266 · poc
https://github.com/tdquang266/MDC
nomisec TROJAN 1 stars
by iswaxan · poc
https://github.com/iswaxan/JailedCement
nomisec WORKING POC
by LumberjackStorys · poc
https://github.com/LumberjackStorys/CVE
nomisec WRITEUP
by daviszhto · poc
https://github.com/daviszhto/overwrite
nomisec WRITEUP
by Code2Crusader · poc
https://github.com/Code2Crusader/46689
nomisec WORKING POC
by 69camau · poc
https://github.com/69camau/sw1tch
nomisec WORKING POC
by ahkecha · local
https://github.com/ahkecha/McDirty
vulncheck_xdb WORKING POC
local
https://github.com/Lrdsnow/PureKFD
vulncheck_xdb WORKING POC
local
https://github.com/BomberFish/Mandela-Rewritten
metasploit WORKING POC EXCELLENT
by Ian Beer, Zhuowei Zhang, timwr · rubypocosx
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/osx/local/mac_dirty_cow.rb

Scores

CVSS v3 7.0
EPSS 0.8533
EPSS Percentile 99.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2022-12-13
CWE
CWE-362
Status published
Products (6)
apple/ipados < 15.7.2
apple/iphone_os < 15.7.2
apple/macos < 11.7.2
apple/safari < 16.2
apple/tvos < 16.2
apple/watchos < 9.2
Published Dec 15, 2022
Tracked Since Feb 18, 2026