PT-2021-7581 · Apple · Apple Macos
R3Ggi
+4
·
Published
2021-12-22
·
Updated
2025-08-12
·
CVE-2022-26696
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
macOS versions prior to 12.4
Description
The issue is related to a sandboxed process that may be able to circumvent sandbox restrictions. This is due to insufficient access control when handling XPC messages in the LaunchServices service of Mac OS. Exploitation of this issue may allow an attacker to bypass security restrictions and escalate their privileges. The issue was addressed with improved environment sanitization.
Recommendations
For versions prior to 12.4, update to macOS Monterey 12.4 to fix the issue. As a temporary workaround, consider restricting access to the LaunchServices to minimize the risk of exploitation.
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apple Macos