Input validation error in macOS - CVE-2022-26776
Published: May 16, 2022
Vulnerability identifier: #VU63263
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-26776
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input in libresolv. A remote attacker can pass specially crafted input to the application and execute arbitrary code on the system.
Affected software
macOS
watchOS
iPadOS
Apple iOS
tvOS
watchOS
iPadOS
Apple iOS
tvOS
How to mitigate CVE-2022-26776
Install updates from vendor's website.
macOS - addressed in versions 12.4 21F79, 11.6.6 20G624
watchOS - update to 8.6 19T572
iPadOS - update to 15.5 19F77
Apple iOS - update to 15.5 19F77
tvOS - update to 15.5 19L570
watchOS - update to 8.6 19T572
iPadOS - update to 15.5 19F77
Apple iOS - update to 15.5 19F77
tvOS - update to 15.5 19L570