Buffer overflow in macOS - CVE-2022-26764
Published: May 16, 2022
Vulnerability identifier: #VU63259
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-26764
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error within the OS kernel subsystem. A local user can trigger memory corruption and bypass kernel memory mitigations to execute arbitrary code.
Affected software
macOS
watchOS
iPadOS
Apple iOS
tvOS
watchOS
iPadOS
Apple iOS
tvOS
How to mitigate CVE-2022-26764
Install updates from vendor's website.
macOS - update to 12.4 21F79
watchOS - update to 8.6 19T572
iPadOS - update to 15.5 19F77
Apple iOS - update to 15.5 19F77
tvOS - update to 15.5 19L570
watchOS - update to 8.6 19T572
iPadOS - update to 15.5 19F77
Apple iOS - update to 15.5 19F77
tvOS - update to 15.5 19L570