Historical publication
The vulnerabilities and patch versions below describe the January 2022 advisory. They do not establish present-day patch compliance.
Microsoft 365 consent phishing
A malicious application called Upgrade used OAuth request links to obtain access to email, contacts and calendars. Consent supplied a token that could remain useful until expiry or revocation.
Controls discussed in the advisory
- Restrict user consent for illegitimate applications.
- Detect and block consent-phishing messages.
- Identify malicious applications through cloud-app monitoring.
Apple updates
CVE-2022-22587 concerned kernel-level code execution and was reported exploited. CVE-2022-22594 concerned cross-origin exposure of sensitive information.
| Product | 2022 update referenced |
|---|---|
| macOS Monterey | 12.2 |
| macOS Big Sur | 11.6.3 |
| macOS Catalina | Security Update 2022-001 |
| Safari | 15.3 |
The original advisory also covered eight arbitrary-code-execution vulnerabilities.
