PT-2022-18017 · Apple · Apple Macos
Joshua Mason
·
Published
2022-05-16
·
Updated
2023-10-31
·
CVE-2022-26704
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
macOS versions prior to 12.4
Description
A validation issue existed in the handling of symlinks, which has been addressed with improved validation of symlinks. This issue may allow an app to gain elevated privileges.
Recommendations
For versions prior to 12.4, update to macOS Monterey 12.4 to resolve the issue. As a temporary workaround, consider restricting the use of symlinks to minimize the risk of exploitation.
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apple Macos