Injection Issue in Xcode Products by Apple
CVE-2022-42797
7.8HIGH
Summary
An injection vulnerability was identified in Xcode, allowing a malicious application to potentially acquire root privileges due to improper input validation. This issue was rectified in Xcode 14.1, enhancing the overall security posture by ensuring robust checks on user input.
Affected Version(s)
Xcode < 14.1
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved