CVE-2022-26775

An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4. An attacker may be able to cause unexpected application termination or arbitrary code execution.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
appleCNA
---
---
CVEADP
---
---
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 44%
VendorProductVersion
applemac_os_x
10.15 ≤
𝑥
< 10.15.7
applemac_os_x
10.15.7
applemac_os_x
10.15.7:security_update_2020
applemac_os_x
10.15.7:security_update_2020-001
applemac_os_x
10.15.7:security_update_2020-005
applemac_os_x
10.15.7:security_update_2020-007
applemac_os_x
10.15.7:security_update_2021-001
applemac_os_x
10.15.7:security_update_2021-002
applemac_os_x
10.15.7:security_update_2021-003
applemac_os_x
10.15.7:security_update_2021-006
applemac_os_x
10.15.7:security_update_2021-007
applemac_os_x
10.15.7:security_update_2021-008
applemac_os_x
10.15.7:security_update_2022-001
applemac_os_x
10.15.7:security_update_2022-002
applemac_os_x
10.15.7:security_update_2022-003
applemac_os_x
10.15.7:supplemental_update
applemacos
12.0.0 ≤
𝑥
< 12.4
𝑥
= Vulnerable software versions