Out-of-Bounds Write Vulnerability in Apple macOS Products
CVE-2022-26748

8.8HIGH

Key Information:

Vendor
Apple
Vendor
CVE Published:
26 May 2022

Summary

An out-of-bounds write vulnerability has been identified in Apple macOS, which can be exploited through maliciously crafted web content. This flaw arises from improper input validation, potentially allowing an attacker to execute arbitrary code on the affected system. Apple has provided updates in Security Update 2022-004 for Catalina, as well as for macOS Monterey 12.4 and Big Sur 11.6.6, to mitigate this concern.

Affected Version(s)

macOS < 11.6

macOS < 12.4

Security Update - Catalina < 2022

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.