/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Overview of macOS vulnerabilities, some actively exploited, that Apple fixed in Monterey but left unfixed in some supported, older versions including Big Sur

Wednesday, April 6, 2022 // (IG): BB //Weekly Sponsor: Cloakedentryco Arnold Zafra / The Mac Observer : Apple Fails to Patch Big Sur and Catalina, Leaves Older Macs Vulnerable to Two Security Exploits Tweets: Matt Rosenberg / @mattyrosen : WTF @apple? As if Big Sur were some kind of EOL OS. https://www.intego.com/... Charles / @chasapple : @theJoshMeister @Apple A zero day I reported to Apple back in late August 2009 is still being actively exploited today, also last I knew Chromium is also affected by the same exploit.

The Mac Security Blog Joshua Long

Context & Ripple Effects

This lands mid-way through an unusually heavy patch year for Apple: by February the company had already shipped its third zero-day fix of 2022 with the WebKit update to iOS 15.3.1 and Monterey 12.2.1. The April report adds a twist — the fixes went to Monterey only, while Big Sur and Catalina, still supported, were left carrying known, actively exploited vulnerabilities.

That asymmetry echoes an older pattern: Apple has patched desktop zero-days under active attack before, as in its 2016 Safari and OS X emergency updates tied to NSO-linked exploits. What changed by late 2022 is that Apple reversed course and extended fixes back to Big Sur, shipping macOS Big Sur 11.7 alongside Monterey 12.6 — making this April gap look like a lapse rather than policy.

First-order effects

  • Mac users on Big Sur and Catalina stay exposed to vulnerabilities that are being exploited in the wild even though their OS versions are officially supported, while Monterey users get the same fixes immediately.

Second-order effects

  • Attackers rationally concentrate on the unpatched installed base once Monterey fixes reveal the flaws, and IT teams face a forced choice between upgrading fleets to Monterey (and often newer hardware) or accepting known-active risk.

Third-order effects

  • If 'supported' stops meaning 'patched,' Apple faces pressure to either commit to backporting security fixes across its supported window or shorten and communicate its effective end-of-life timeline honestly — the September Big Sur 11.7 release suggests the backport path won out.

The trend: Amid a record run of actively exploited Apple zero-days through 2022, the company's patching discipline is being tested on whether security fixes extend to all supported OS versions or only the latest one.

Discussion

  • @chasapple Charles on x
    @theJoshMeister @Apple A zero day I reported to Apple back in late August 2009 is still being actively exploited today, also last I knew Chromium is also affected by the same exploit.
  • @mattyrosen Matt Rosenberg on x
    WTF @apple? As if Big Sur were some kind of EOL OS. https://www.intego.com/...