Input validation error in macOS - CVE-2022-26708
Published: May 16, 2022
Vulnerability identifier: #VU63264
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-26708
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input in libresolv. A remote attacker can pass specially crafted input to the application and execute arbitrary code on the system.
Affected software
macOS
watchOS
iPadOS
Apple iOS
tvOS
watchOS
iPadOS
Apple iOS
tvOS
How to mitigate CVE-2022-26708
Install updates from vendor's website.
macOS - update to 12.4 21F79
watchOS - update to 8.6 19T572
iPadOS - update to 15.5 19F77
Apple iOS - update to 15.5 19F77
tvOS - update to 15.5 19L570
watchOS - update to 8.6 19T572
iPadOS - update to 15.5 19F77
Apple iOS - update to 15.5 19F77
tvOS - update to 15.5 19L570