CVE-2022-48575
Received Received - Intake
macOS Login Window Bypass Vulnerability

Publication date: 2026-06-10

Last updated on: 2026-06-11

Assigner: Apple Inc.

Description
A person with access to a Mac may be able to bypass Login Window. A consistency issue was addressed with improved state handling. This issue is fixed in macOS Monterey 12.4.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-10
Last Modified
2026-06-11
Generated
2026-06-11
AI Q&A
2026-06-11
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
apple macos to 12.4 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability allows a person with physical access to a Mac to bypass the Login Window, potentially gaining unauthorized access to the system.

The issue was caused by a consistency problem that has been addressed with improved state handling.

The vulnerability is fixed in macOS Monterey version 12.4.

Impact Analysis

If exploited, this vulnerability could allow an unauthorized person with physical access to your Mac to bypass the Login Window and access your system without proper authentication.

This could lead to unauthorized access to your files, applications, and potentially sensitive information stored on the device.

Mitigation Strategies

To mitigate this vulnerability, update your Mac to macOS Monterey 12.4 or later, where the issue has been fixed.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2022-48575. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart