PT-2021-7581 · Apple · Apple Macos

R3Ggi

+4

·

Published

2021-12-22

·

Updated

2025-08-12

·

CVE-2022-26696

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions macOS versions prior to 12.4
Description The issue is related to a sandboxed process that may be able to circumvent sandbox restrictions. This is due to insufficient access control when handling XPC messages in the LaunchServices service of Mac OS. Exploitation of this issue may allow an attacker to bypass security restrictions and escalate their privileges. The issue was addressed with improved environment sanitization.
Recommendations For versions prior to 12.4, update to macOS Monterey 12.4 to fix the issue. As a temporary workaround, consider restricting access to the LaunchServices to minimize the risk of exploitation.

Fix

Protection Mechanism Failure

Weakness Enumeration

Related Identifiers

BDU:2023-00150
CVE-2022-26696
ZDI-22-1066

Affected Products

Apple Macos