PT-2022-7005 · Apple · Macos Catalina+7
Linus Henze
·
Published
2022-05-16
·
Updated
2026-01-18
·
CVE-2022-26766
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Apple tvOS versions prior to 15.5
Apple iOS versions prior to 15.5
Apple iPadOS versions prior to 15.5
Apple watchOS versions prior to 8.6
Apple macOS Big Sur versions prior to 11.6.6
Apple macOS Monterey versions prior to 12.4
Apple macOS Catalina versions prior to Security Update 2022-004
Description
A certificate parsing issue was addressed with improved checks, which may allow a malicious app to bypass signature validation. This issue is related to errors in the certificate authentication procedure.
Recommendations
For Apple tvOS versions prior to 15.5, update to tvOS 15.5 or later.
For Apple iOS versions prior to 15.5, update to iOS 15.5 or later.
For Apple iPadOS versions prior to 15.5, update to iPadOS 15.5 or later.
For Apple watchOS versions prior to 8.6, update to watchOS 8.6 or later.
For Apple macOS Big Sur versions prior to 11.6.6, update to macOS Big Sur 11.6.6 or later.
For Apple macOS Monterey versions prior to 12.4, update to macOS Monterey 12.4 or later.
For Apple macOS Catalina versions prior to Security Update 2022-004, apply Security Update 2022-004 or later.
Exploit
Fix
Improper Authentication
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apple Macos
Ios
Ipados
Macos Big Sur
Macos Catalina
Macos Monterey
Tvos
Watchos