Input validation error in macOS - CVE-2022-26751
Published: May 16, 2022 / Updated: May 26, 2022
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input within the processing of HEIC files in the VTDecoderXPCService process in the AppleGraphicsControl. A remote attacker can trick the victim to open a specially crafted image and execute arbitrary code on the system.
Affected software
Apple iOS
iPadOS
iTunes
How to mitigate CVE-2022-26751
iTunes - update to 12.12.4
Apple iOS - update to 15.5 19F77
iPadOS - update to 15.5 19F77