back to article Apple patched critical flaws in macOS Monterey but not in Big Sur nor Catalina

Apple last week patched two actively exploited vulnerabilities in macOS Monterey yet has left users of older supported versions of its desktop operating system unprotected. In a blog post on Tuesday, security biz Intego said fixes applied to address CVE-2022-22675 (AppleAVD bug) and CVE-2022-22674 (Intel Graphics Driver bug) …

  1. wolfetone Silver badge

    There is an official update available from Apple

    That update is - buy a new Mac.

    That's their business model. But don't remember this when it happens again in a few years time and they decide to not bother updating an "old" OS, regardless of how widely used it is.

    They are an absolute shower of bastards. Between Emma mattresses and Apple, it's only Wednesday and all my Zen has gone.

    1. Anonymous Coward
      Anonymous Coward

      Re: There is an official update available from Apple

      So from what I can work out, this is a webkit bug that applies to playing audio and video within Safari?

      I rarely use Safari and it's never to access media content. Anything to be worried about?

      1. Korev Silver badge
        Pirate

        Re: There is an official update available from Apple

        Although you maybe don't go to say Youtube; think about how many websites autoplay video and/or have adverts which do.

        1. Anonymous Coward
          Anonymous Coward

          Re: There is an official update available from Apple

          Safari for me is logging into Microsoft 365 admin, Google sheets and sometimes Shopify admin. So no autoplay videos anywhere.

      2. doublelayer Silver badge

        Re: There is an official update available from Apple

        WebKit can be used as a component for displaying HTML content inside other applications. Not all applications that do so will use it. There's also the possibility that Mac OS would open Safari instead of your preferred browser for certain types of resources, meaning that someone could tailor a link to make it open Safari. Your risk is still lower from someone trying an untargeted infection.

    2. Anonymous Coward
      Anonymous Coward

      Re: There is an official update available from Apple

      I'm not aware of any Mac which will run Catalina and Big Sur but not Monterey so no need to buy a new Mac.

      Just hit the update button.

      (I understand there are reasons why people can't upgrade such as unsupported software and such and people in this situation have my sympathy)

      1. VoiceOfTruth Silver badge

        Re: There is an official update available from Apple

        -> Just hit the update button

        I have a Catalina machine. I took at look at Big Sur and if offered me nothing that I wanted. Am I supposed to update a whole OS to get a driver update?

        1. Anonymous Coward
          Anonymous Coward

          Re: There is an official update available from Apple

          Yes, you're two releases behind the main line.

          Are Microsoft still patching Windows 8.1?

          What exactly do you lose by holding back?

          1. nichomach

            Re: There is an official update available from Apple

            "Are Microsoft still patching Windows 8.1?"

            Pro? Yes. Drops out of support next year.

          2. VoiceOfTruth Silver badge

            Re: There is an official update available from Apple

            -> What exactly do you lose by holding back?

            There is nothing in Big Sur that I want. It offers me nothing.

            1. envida

              Re: There is an official update available from Apple

              -> What exactly do you lose by holding back?

              -->There is nothing in Big Sur that I want. It offers me nothing.

              ...Apart from a secure system?

              1. VoiceOfTruth Silver badge

                Re: There is an official update available from Apple

                For a single driver I must update a whole OS? Go back to school and learn something.

            2. GiantKiwi

              Re: There is an official update available from Apple

              Just update the mac, stop being facetious over something so meaningless.

              1. Alan Bourke

                Re: There is an official update available from Apple

                This is like those gobshites who stay on Windows XP because their brain hurts or something.

                1. 43300 Silver badge

                  Re: There is an official update available from Apple

                  And claim that 'if it ain't broke, why fix it?'. If someone then points out the significant security implications of running a system which hasn't been patched for years - i.e. very much is 'broke' - they have no answer (and may well not even understand the issue).

                  Usually tends to be W7 rather than XP now, but the same applies!

              2. georgezilla Silver badge

                Re: There is an official update available from Apple

                So you have no actual reason for them to update the "whole" OS, for just a driver?

                Except for an irrelevant, smart ass reply?

            3. Anonymous Coward
              Anonymous Coward

              Re: There is an official update available from Apple

              Except the security patches you are whining about not having you mean?

              1. VoiceOfTruth Silver badge

                Re: There is an official update available from Apple

                I've had regular security patches for Catalina. This is a driver update issue that happens to also be a security issue.

          3. F. Frederick Skitty Silver badge

            Re: There is an official update available from Apple

            Windows 8.1 was released in 2013, and is still supported by Microsoft. macOS Catalina was released in 2019, and judging by the article isn't really supported.

            1. Anonymous Coward
              Anonymous Coward

              Re: There is an official update available from Apple

              Apple is greedy and lazy. History is factual proof.

          4. Anonymous Coward
            Anonymous Coward

            Re: There is an official update available from Apple

            Eh, Windows 8.1 came out in 2013. Catalina came out in 2019. So more accurate to ask if MS is still patching 19H2, which for some of us is still a "Yes" for a few more weeks.

          5. georgezilla Silver badge

            Re: There is an official update available from Apple

            " ... What exactly do you lose by holding back? ... "

            It's not about what you "lose" but what you retain ...............

            Control over what you own.

            Especially important in a walled garden.

      2. Crypto Monad Silver badge

        Re: There is an official update available from Apple

        > I'm not aware of any Mac which will run Catalina and Big Sur but not Monterey so no need to buy a new Mac.

        3rd generation Retina Macbook Pro (Late 2013 / Mid 2014) runs Big Sur but not Monterey.

        https://en.wikipedia.org/wiki/MacBook_Pro_(Intel-based)

        1. Anonymous Coward
          Anonymous Coward

          Re: There is an official update available from Apple

          Fair enough.

          I'm now aware of one.

        2. Anonymous Coward
          Anonymous Coward

          Re: There is an official update available from Apple

          I have one of these and confirm that this is true. However I do get nice adverts telling me to upgrade every now and then.

        3. Snapper

          Re: There is an official update available from Apple

          Officially, these are not supported after macOS Catalina 10.15.7

          iMac (21.5-inch, Late 2012)

          iMac (27-inch, Late 2012)

          iMac (21.5-inch, Early 2013)

          iMac (21.5-inch, Late 2013)

          iMac (27-inch, Late 2013)

          Mac mini (Late 2012)

          Mac mini Server (Late 2012)

          MacBook Air (11-inch, Mid 2012)

          MacBook Air (13-inch, Mid 2012)

          MacBook Pro (13-inch, Mid 2012)

          MacBook Pro (15-inch, Mid 2012)

          MacBook Pro (Retina, 15-inch, Mid 2012)

          MacBook Pro (Retina, 13-inch, Late 2012)

          MacBook Pro (Retina, 13-inch, Early 2013)

          MacBook Pro (Retina, 15-inch, Early 2013)

          1. katrinab Silver badge
            Meh

            Re: There is an official update available from Apple

            Which are all about 9-10 years old.

            It is only pretty recently that we would have considered a 9 year old computer to be anything other than utterly obsolete.

            The ones I looked at (mid 2012 MacBook Pro and early 2013 MacBook Pro) have Ivy Bridge CPUs, and they are very useable for anything other than gaming. But if you wanted a gaming machine, you wouldn't have bought a Mac.

            1. Ace2 Silver badge

              Re: There is an official update available from Apple

              My 2014 iMac finally got dropped as of Monterey. I wish it hadn’t been - it still works perfectly, and the 3D perf is still better than an M1, Intel built-in, or modest eGPU.

              1. CapeCarl

                Re: There is an official update available from Apple

                My "iMac (Retina 5K, 27-inch, Late 2014)" is still my main home personal computer...Works fine...Big Sur seems to be the end of the OS line for this mostly-NetFlix/email/VirtualBox/YouTube/Udemy-course/Chrome-surfing beast.

                With a 2nd screen, it was a great work-via-VPN Terminal/SSH/dashboard-viewing beast monitoring 1,000s of Linux workerBees during my WFH Sys Admin shifts.

            2. doublelayer Silver badge

              Re: There is an official update available from Apple

              That's for Mac OS two versions old. If we consider Big Sur, there are machines stuck with it that are only six years old. Let's consider the MacBook Pro 13-inch from 2014 (discontinued May 2015, so a little under seven years ago). It has a Haswell-series CPU. Now let's consider the MacBook Air that was released in 2020 (the last with an Intel processor). It's a newer chip. Memory-wise, they have the same amount. Storage-wise, the disk interfaces are the same speed and the disk capacity is the same. Processing-wise, the chip has the same number of cores and they benchmark similarly (the single-threaded benchmark is almost exactly equal, whereas the Air gets a slightly higher multithreaded score). True, the older machine does that with a 28W processor and the newer with a 9W one, but that only affects the battery life. In short, there's no technical problem with the older one's performance that prevents it from running the newer OS.

              That's not the newest machine that's getting cut off. I used that one to have a valid comparison (had I used the 15-inch laptop that uses a 47W quad-core chip, I could have given you even better proof about the performance issue). The latest machine not to get the update is the MacBook Retina from 2015 (discontinued April 2016), narrowly beating out an iMac. This means that they're only keeping support up for six years before they allow security vulnerabilities to remain deliberately unpatched.

              Contrary to your claims, it isn't just now that you would expect someone to use a computer longer than six years. I know people who are still using computers from 2010, and I'm talking about people who run Windows on them and never upgraded any of the internals. For that matter, I also know people using Macs from that long ago, though unlike the Windows people, they're stuck without patches. We all know that, if you make certain updates like installing an SSD and run efficient software, you can exceed that length easily.

              1. Anonymous Coward
                Anonymous Coward

                Re: There is an official update available from Apple

                I still have a 2008 Macbook that I use from time to time. It still works, hasn't caught fire yet, and doesn't bitch much. Can't be in any hurry when using it, though, as it's a tad slow.

            3. nagyeger

              Re: There is an official update available from Apple

              It is only pretty recently that we would have considered a 9 year old computer to be anything other than utterly obsolete.

              Maybe you have that attitude. Maybe you're a gamer who needs those extra super dooper graphics cards, or maybe you're a micro$oft victim?

              Or do you buy machines that barely have enough RAM when they're new?

              I'd consider a 20 year old computer obsolete and a 9 year old one ' due for replacement in the next 6 years', if I'm talking desktops.

              Case in point, this machine I'm on at the moment, has a Xeon E3-1275, released 2013, still going strong.

              My old Turion64-based laptop (2005) is still very usable if plugged in, but I need to class it as pretty much obsolete, but only because of software bloat and it can't take more than 1GB of RAM.

            4. gnwiii

              Re: There is an official update available from Apple

              "It is only pretty recently that we would have considered a 9 year old computer to be anything other than utterly obsolete."

              Yes -- only since 2014 Intel has managed to produce new chips that provide only marginal improvements for many use cases. My wife gave me her late 2013 iMac 27" after she bought an Apple silicon system. The iMac is only a bit slower than Intel (all core i5) systems purchased in the last 3 years -- not enough that many users would notice. Current Apple silicon systems are very noticeably faster. In my field, that difference means we can start to introduce improvements that were put on hold because the run times would have been excessive.

          2. VicMortimer Silver badge
            Flame

            Re: There is an official update available from Apple

            To be fair, any Mac that will "officially" run 10.14 will also run 12.

            Most Macs that will only "officially" run 10.13 will also run 12.

            OpenCore Legacy Patcher is your friend.

            (Of course, I'm typing this on a 2012 15" MBP running 10.14 and have no intention of downgrading it to anything more recent because I'm unwilling to give up 32-bit software support. I've got other Macs running 12, but this is easily as fast as those newer Macs for what I do.)

      3. Eclectic Man Silver badge
        Unhappy

        Re: There is an official update available from Apple

        "I understand there are reasons why people can't upgrade such as unsupported software and such and people in this situation have my sympathy"

        Not just unsupported software. My Epson Stylus PHOTO 1290 A3+ printer still works, but does not even have a driver for Big Sur, so I have to leave one of my computers on an earlier OS, and copy files I want to print across. I upgraded the laptop I use exclusively for internet financials (banking) and other offline stuff when it would no longer support an OS that had a browser compatible with my bank's personal banking interface.

        Of course MS is not without fault either, as a friend of mine had a Microsoft webcam he used for baby monitoring which failed on one of the Windows updates a few years ago and he discovered was no longer supported.

        1. Anonymous Coward
          Anonymous Coward

          Re: There is an official update available from Apple

          I'm guessing this is to do with 32bit code being blocked. Blame Epson for not releasing 64 bit drivers.

          1. Richard 12 Silver badge

            Re: There is an official update available from Apple

            Catalina blocked 32bit. So it's not Epson, it's Apple changing something else without warning.

            Drivers on macOS are a really rather horrible mess that changes all the time. Sadly, Microsoft are setting off down the same dark path :(

            1. O RLY

              Re: There is an official update available from Apple

              "Sadly, Microsoft are setting off down the same dark path :("

              Or returning to it. Windows Plug-n-play up until XP SP2 was usually plug-n-pray, then curse, and go hunting for a driver.

        2. Captain Scarlet

          Re: There is an official update available from Apple

          Are you sure, a quick Google shows it should have a driver?

          I must admit I was looking for a Universal Print Driver like most manufacturers do for Windows (tbh I would recommend as they are normally light weight and include mostly everything needed)

          1. Eclectic Man Silver badge
            Happy

            Re: There is an official update available from Apple

            @Captain Scarlet

            Thanks very much. Yes it does have a driver. I had not searched for a while so my information was out of date.

            1. Captain Scarlet
              Pint

              Re: There is an official update available from Apple

              Well by the looks of it, the drivers were released years after the actual MacOS updates were released and like most places there doesn't seem to be a place to get notifications.

        3. Tim99 Silver badge
          Gimp

          Re: There is an official update available from Apple

          If the driver doesn’t do what you want, it’s possible that Apple CUPS (Common UNIX printing system - cups.org) might work if you don’t need scanning. OpenPrinting lists your printer as supported https://openprinting.github.io/

          To enable it, use the terminal command ‘cupsctl WebInterface=yes’, then try ‘man cups’. Then see if you can open http://localhost:631/printers/ in Safari…

      4. Anonymous Coward
        Alien

        Re: There is an official update available from Apple

        I'm not aware of any Mac which will run Catalina and Big Sur but not Monterey so no need to buy a new Mac.

        Perhaps you should check before sprouting bullshit? Am typing this on a 13in late 2013 Macbook Pro which is running 11.6.5 but you will find, if you bothered to look, is not in Apple's supported hardware list for 12.

        Perhaps that is why you sprout as anonymous idiot.

      5. Richard Pennington 1

        Re: There is an official update available from Apple

        Anon Coward, you are either uninformed or misinformed.

        I am typing this on my (newly-acquired second-hand) iMac (15,1) which has recently been updated from Catalina to Big Sur ... and which cannot run Monterey. It dates from 2014.

        Its predecessor (iMac 14,1 from 2013, now decommissioned) could be updated only as far as Catalina.

      6. This post has been deleted by its author

      7. 43300 Silver badge

        Re: There is an official update available from Apple

        There definietely are some - compare:

        https://support.apple.com/kb/sp833?locale=en_GB

        and

        https://support.apple.com/en-us/HT212551

        Might well be workarounds, but most users won't do that.

    3. Charlie Clark Silver badge

      Re: There is an official update available from Apple

      It's not quite that bad: hardware tends to receive OS updates for 5-6 years, which in terms of a business device, is reasonable and better than many Windows PCs, which by that time may still be receiving OS updates from Microsoft but the manufacturer has long since stopped caring.

      That said, the policy is somewhat arbitrary and annoying. I have a perfectly good 2010 MacBook Pro with a refurbished battery that, for Apple's own reasons, can't go beyond Lion. So, it's just sitting around waiting to go on ebay, because there is at least still a market for it.

      I'm still on Catalina with my 2020 Intel MBP and my reserve 2016 MBP (you have to have a reserve not least because of battery issues with Macs and this one too has a new battry) because I'm waiting for Apple to fix all the problems with their new architecture and merging with IOS. And I also need to have the same basis for hot-swapping, in case of hardware failure.

      That the patch for the graphics driver has not been released for the older versions is disgraceful, though I assume Apple will get round to it when it suits. IANAL but I don't think the argument that there is a new version of the OS would really wash here because the new OS comes with new T&Cs.

      1. Captain Scarlet

        Re: There is an official update available from Apple

        Have had my nans Windows 10 Dell Laptop be useless after applying an updated, basically would never finish any larger updates as the intel chipset driver were not actually supported after Windows 8.1 (Thanks MS for just popping up upgrade and doing it anyway). Ended up buying a cheap ProBook to replace it in the end.

        1. Captain Scarlet

          Re: There is an official update available from Apple

          Ok downvoter maybe I wasn't clear, the machine came with Windows 7 Home, was around 3 years old when Windows 10 was released, auto updated but failed and was in an endless loop (So install via the media creation tool). Same occured every major update, Dell website itself said Windows 10 was not supported. Checking this it appeared to be because of the Intel chipset used, the intel site itself provided drivers for Windows 7 and I believe 8.1, thats it.

      2. cd

        Re: There is an official update available from Apple

        There are updates for that model from here...http://dosdude1.com/software.html

        They will help you download the OS, see menu bar, and then make an install stick with it. Boot from it, install the OS, then it has a patcher with the checkboxes already checked for your model, which you can alter if you like.

        I have used his High Sierra 10.13 patcher on my mid-2009 and it worked fine, but I didn't like being forced to AFS or the early AFS performance and it seemed to use a bit more battery, which I'm often on, so I went back to 10.9.

        Honestly the Jony Ive years of MacOS were characterised by poor visual design decisions. I get that these people are all in their elite club, but they do have to answer to customers at least a little bit, thus more ports returning to MBP's.

        If they could get away with it, they'd sell a touch screen that grabbed the contents of your mind and uploded that to their cloud, while charging 10k fro the privilege.

    4. FIA Silver badge

      Re: There is an official update available from Apple

      That update is - buy a new Mac.

      It is. (Well, or one that's less than 7ish years old).

      That's their business model.

      As oppose to all those other companies that just do it for the lulz?

      But don't remember this when it happens again in a few years time and they decide to not bother updating an "old" OS, regardless of how widely used it is.

      Apple have supported hardware for about 7 years for a very long time now. All that's happened is the slowing progression of technology means more of those old machines are still viable to use; but that's okay, just bung Linux on them.

    5. The_Wisest_One

      Re: There is an official update available from Apple

      Remind us again of Microsofts business Model regarding Windows 11....

      1. 43300 Silver badge

        Re: There is an official update available from Apple

        Yes, they too are now playing the same game.

        Didn't apply with previous version - I've got some 10-year-old devices running W10 in very undemanding roles.

  2. Anonymous Coward
    Pint

    @wolfetone

    Oh dear, not happy at all are you. Still, at least you didn't use that very tired old tagline about Macs not getting viruses. No doubt someone will and think they are being clever and "edgy".

    Anyway, sod Zen. Go get yoursen a few of liveners....

  3. bazza Silver badge

    Holy Microsoft?

    This makes MS look like saints. Well, at least up until they drop support for Windows 10 holdouts.

    1. aerogems Silver badge

      Re: Holy Microsoft?

      Microsoft provides clear and predictable support roadmaps for every OS even before it's released. Every major release gets 10-years of support, and on rare occasion they've extended that. Apple does this for their hardware, where they commit to support it for 5-years after release, but with their software they never bother to tell anyone when they stop supporting a particular version. You're left to divine it indirectly via methods like this, where some large security issue is patched in one version but not the other(s).

      1. bazza Silver badge

        Re: Holy Microsoft?

        Indeed yes, and to make it even more workable MS are very slow to remove frameworks from their OSes. So even if an OS is obsoleted, that generally does not wipe out software written for it, not for generations. I say that's pretty good for us end users.

      2. 43300 Silver badge

        Re: Holy Microsoft?

        Suspect they might have to extend W10 if (as is likely) corporate take-up of W11 in a couple of years is still crap.

        Did anyone else watch their online presentation on W11 on Monday? Aimed at IT pros and came across as a desperate plea to convince us that W11 is fantastic for business use. Was all hype and little content, and is unlikely to have swayed anyone in the normally-cynical IT profession!

        1. bazza Silver badge

          Re: Holy Microsoft?

          I didn't see it, but I recognise the smell of it. I've not tried 11 yet, but I strongly suspect that you'll be proved correct, judging by everone's "Meh" (at best) response!

  4. Anonymous Coward
    Anonymous Coward

    It is just the upgrade whip in action. Time to shell out some coin for a new Mac, people. You bought into the walled garden's gravy train, so pay up!

    Somebody in management wants a new mega-yacht...

  5. Tim99 Silver badge
    Gimp

    Numbers?

    I’m not sure where the 35-40% came from. Statcounter has the number of Catalina users at over 84% worldwide

    1. Anonymous Coward
      Anonymous Coward

      Re: Numbers?

      Lies, damned lies, and statistics.

  6. Ben Trabetere

    This gets me in a 'glass half full' kind of mood

    Looking on the bright side, I have contacts with several businesses and non-profits that have a habit of "upgrading" their macBook Pros when upgrading macOS proves to be troublesome. I am happy to take them off their hands. Most take to Linux very easily, and most go on to live happy lives at a non-profit that provides after-school activities.

  7. IGotOut Silver badge

    Or maybe, just maybe...

    ..As it says for the Intel bug, they may not be vulnerable.

  8. aerogems Silver badge

    Should be interesting

    I have a work issued laptop that's too old to officially run the latest and greatest. I'm sure there are some unofficial hacks to get it to run the newer OS, but I'm not going to do that on a work laptop.

  9. DS999 Silver badge

    They always release patches for the most recent OS first

    That's how they did it with that NSO 0 day last fall.

    They've even released patches for unsupported OS versions on a couple occasions for iOS for very serious flaws (I remember it at least once for a 0 day and they also did it for the GPS rollover) I don't have a Mac so I don't know if they do that with macOS also.

  10. DerekCurrie
    Facepalm

    Another Era Of Apple Software Security Shaming

    Apple blundering its software security isn't new. Of course, in the past they'd been the target of trolls and cyber propagandists who envied Apple software security. But that security began to fall away during the transition to Intel Macs in 2006. Out of that era was born a diverse group of hackers who shamed Apple into taking software security more seriously. Slowly, this resulted into embedded macOS embedded malware security and the iOS 'Walled Garden'. Today, there is a robust selection of third party companies devoted to analyzing Apple security as well as providers of macOS security tools, from firewalls to outgoing Internet connection control to malware detection, isolation and removal.

    However, since circa 2016, Apple has gradually taken their eyes off the software ball and allowed for blunders that are obvious and annoying to users, while neglecting feedback from both users and developers calling for positive change. Apple's declining attention to software security is more of the same. Apparently, It's time for another era of Apple software security shaming.

    Have At You!

    https://idioms.thefreedictionary.com/have+at+you

  11. Kev99 Silver badge

    What about El Cap? It's does just fine and doesn't require spending thousands of dollars for marginally better hardware.

  12. ntsmkfob
    Meh

    Big Sur security update installed yesterday

    Yawn.

  13. gnwiii

    New update from Apple, but the installation is failing

    I have an iMac Retina 2013, running 10.15.7 (Catalina), ini Canada .This morning a macOS security update was "available", but the installer is in a fail loop:

    MacOS could not be installed on your computer. The file "firmlinks" couldn't be opened because there is no such file.. Quit the installer to restart your computer and try again. On restart I get: https://support.apple.com/mac which gets a page titled "If your Mac doesn't start up all the way" which suggests resetting the NVRAM, which gets back to the installer, which fails with the same firmlinks couldn't be opened.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like