Overview of macOS vulnerabilities, some actively exploited, that Apple fixed in Monterey but left unfixed in some supported, older versions including Big Sur
Wednesday, April 6, 2022 // (IG): BB //Weekly Sponsor: Cloakedentryco Arnold Zafra / The Mac Observer : Apple Fails to Patch Big Sur and Catalina, Leaves Older Macs Vulnerable to Two Security Exploits Tweets: Matt Rosenberg / @mattyrosen : WTF @apple? As if Big Sur were some kind of EOL OS. https://www.intego.com/... Charles / @chasapple : @theJoshMeister @Apple A zero day I reported to Apple back in late August 2009 is still being actively exploited today, also last I knew Chromium is also affected by the same exploit.
Context & Ripple Effects
This lands mid-way through an unusually heavy patch year for Apple: by February the company had already shipped its third zero-day fix of 2022 with the WebKit update to iOS 15.3.1 and Monterey 12.2.1. The April report adds a twist — the fixes went to Monterey only, while Big Sur and Catalina, still supported, were left carrying known, actively exploited vulnerabilities.
That asymmetry echoes an older pattern: Apple has patched desktop zero-days under active attack before, as in its 2016 Safari and OS X emergency updates tied to NSO-linked exploits. What changed by late 2022 is that Apple reversed course and extended fixes back to Big Sur, shipping macOS Big Sur 11.7 alongside Monterey 12.6 — making this April gap look like a lapse rather than policy.
First-order effects
- Mac users on Big Sur and Catalina stay exposed to vulnerabilities that are being exploited in the wild even though their OS versions are officially supported, while Monterey users get the same fixes immediately.
Second-order effects
- Attackers rationally concentrate on the unpatched installed base once Monterey fixes reveal the flaws, and IT teams face a forced choice between upgrading fleets to Monterey (and often newer hardware) or accepting known-active risk.
Third-order effects
- If 'supported' stops meaning 'patched,' Apple faces pressure to either commit to backporting security fixes across its supported window or shorten and communicate its effective end-of-life timeline honestly — the September Big Sur 11.7 release suggests the backport path won out.
The trend: Amid a record run of actively exploited Apple zero-days through 2022, the company's patching discipline is being tested on whether security fixes extend to all supported OS versions or only the latest one.