#VU63235 Input validation error in macOS - CVE-2022-26751
Published: May 16, 2022 / Updated: May 26, 2022
macOS
Apple Inc.
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input within the processing of HEIC files in the VTDecoderXPCService process in the AppleGraphicsControl. A remote attacker can trick the victim to open a specially crafted image and execute arbitrary code on the system.