Researchers reported that Apple’s fix for CVE-2021-30724 in the root-privileged CVMServer daemon introduced a new flaw, tracked as CVE-2022-26721, that could be reached from the Safari renderer sandbox on macOS. The bug stemmed from uninitialized cleanup metadata left behind when a bounds check aborted processing, creating a path for attacker-controlled munmap operations on arbitrary memory pages inside the service.
Theori showed the issue could be turned into root code execution by shaping heap contents, using a binary-search-style oracle to infer CVMServer memory layout, and overwriting dyld private-memory function pointers. A proof of concept reportedly read /var/db/SystemKey, which can be used to decrypt macOS keychain files, underscoring the impact of the sandbox escape and privilege-escalation chain. Apple addressed the vulnerability in macOS 12.4 by replacing malloc with calloc to ensure the descriptor buffer was zero-initialized.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Theori stated that Apple fixed CVE-2022-26721 in macOS 12.4 by replacing malloc with calloc to zero-initialize the descriptor buffer. This addressed the uninitialized memory condition in CVMServer.
Theori reported that Apple’s patch for CVE-2021-30724 introduced CVE-2022-26721, an uninitialized memory flaw in the root-privileged CVMServer daemon on macOS. The bug left cleanup metadata uninitialized when a bounds check triggered a break, enabling attacker-controlled munmap calls on arbitrary memory pages.
On June 16, 2022, Theori published technical analysis showing how CVE-2022-26721 could be exploited from the Safari renderer sandbox to achieve root code execution. The proof of concept demonstrated reading /var/db/SystemKey, which could be used to decrypt macOS keychain files.
Trend Micro reported CVE-2021-30724, a CVMServer vulnerability affecting macOS and iOS, in research published on June 3, 2021. The later Theori analysis states Apple’s fix for this issue introduced a new bug.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.