PT-2022-18065 · Apple · Apple Macos+4

Linus Henze

·

Published

2022-05-16

·

Updated

2025-05-30

·

CVE-2022-26765

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions watchOS versions prior to 8.6 tvOS versions prior to 15.5 macOS Monterey versions prior to 12.4 iOS versions prior to 15.5 iPadOS versions prior to 15.5
Description A race condition was addressed with improved state handling, which could allow a malicious attacker with arbitrary read and write capability to bypass Pointer Authentication.
Recommendations For watchOS versions prior to 8.6, update to watchOS 8.6 to resolve the issue. For tvOS versions prior to 15.5, update to tvOS 15.5 to resolve the issue. For macOS Monterey versions prior to 12.4, update to macOS Monterey 12.4 to resolve the issue. For iOS versions prior to 15.5, update to iOS 15.5 to resolve the issue. For iPadOS versions prior to 15.5, update to iPadOS 15.5 to resolve the issue.

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-26765

Affected Products

Apple Macos
Ios
Ipados
Tvos
Watchos