CVE-2022-26702
published 2022-05-26CVE-2022-26702: A use after free issue was addressed with improved memory management. This issue is fixed in watchOS 8.6, tvOS 15.5, iOS 15.5 and iPadOS 15.5. An application…
PriorityP341high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.08%
61.5th percentile
A use after free issue was addressed with improved memory management. This issue is fixed in watchOS 8.6, tvOS 15.5, iOS 15.5 and iPadOS 15.5. An application may be able to execute arbitrary code with kernel privileges.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_15.5_and_ipados | — | — |
| apple | ipados | < 15.5 | 15.5 |
| apple | iphone_os | < 15.5 | 15.5 |
| apple | macos_big_sur | — | — |
| apple | tvos | < 15.5 | 15.5 |
| apple | tvos | — | — |
| apple | watchos | < 8.6 | 8.6 |
| apple | watchos | — | — |
| apple | watchos | >= unspecified < 8.6 | 8.6 |
| apple | watchos | >= unspecified < 15.5 | 15.5 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2022-26702: macOS Big Sur 11.7.5
vendor_apple·2023-03-27·CVSS 7.8
CVE-2022-26702 [HIGH] CVE-2022-26702: macOS Big Sur 11.7.5
Apple Security Update: About the security content of macOS Big Sur 11.7.5
Product: macOS Big Sur
Version: 11.7.5
CVE: CVE-2022-26702
Component: AppleAVD
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A use after free issue was addressed with improved memory management.
Apple
CVE-2022-26702: iOS 15.5 and iPadOS 15.5
vendor_apple·2022-05-16·CVSS 7.8
CVE-2022-26702 [HIGH] CVE-2022-26702: iOS 15.5 and iPadOS 15.5
Apple Security Update: About the security content of iOS 15.5 and iPadOS 15.5
Product: iOS 15.5 and iPadOS
Version: 15.5
CVE: CVE-2022-26702
Component: AppleAVD
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A use after free issue was addressed with improved memory management.
Apple
CVE-2022-26702: watchOS 8.6
vendor_apple·2022-05-16·CVSS 7.8
CVE-2022-26702 [HIGH] CVE-2022-26702: watchOS 8.6
Apple Security Update: About the security content of watchOS 8.6
Product: watchOS
Version: 8.6
CVE: CVE-2022-26702
Component: AppleAVD
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A use after free issue was addressed with improved memory management.
Apple
CVE-2022-26702: tvOS 15.5
vendor_apple·2022-05-16·CVSS 7.8
CVE-2022-26702 [HIGH] CVE-2022-26702: tvOS 15.5
Apple Security Update: About the security content of tvOS 15.5
Product: tvOS
Version: 15.5
CVE: CVE-2022-26702
Component: AppleAVD
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A use after free issue was addressed with improved memory management.
VulDB
Apple iOS/iPadOS up to 15.4.1 AppleAVD use after free (HT213258 / EUVD-2022-31252)
vuldb·2026-05-10·CVSS 7.8
CVE-2022-26702 [HIGH] Apple iOS/iPadOS up to 15.4.1 AppleAVD use after free (HT213258 / EUVD-2022-31252)
A vulnerability marked as critical has been reported in Apple iOS and iPadOS up to 15.4.1. Impacted is an unknown function of the component AppleAVD. This manipulation causes use after free.
The identification of this vulnerability is CVE-2022-26702. The attack can only be executed locally. There is no exploit available.
It is suggested to upgrade the affected component.
GHSA
GHSA-j3wx-x95h-jpch: A use after free issue was addressed with improved memory management
ghsa_unreviewed·2022-05-27
CVE-2022-26702 [HIGH] CWE-416 GHSA-j3wx-x95h-jpch: A use after free issue was addressed with improved memory management
A use after free issue was addressed with improved memory management. This issue is fixed in watchOS 8.6, tvOS 15.5, iOS 15.5 and iPadOS 15.5. An application may be able to execute arbitrary code with kernel privileges.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://seclists.org/fulldisclosure/2023/Mar/21https://support.apple.com/en-us/HT213253https://support.apple.com/en-us/HT213254https://support.apple.com/en-us/HT213258https://support.apple.com/kb/HT213675http://seclists.org/fulldisclosure/2023/Mar/21https://support.apple.com/en-us/HT213253https://support.apple.com/en-us/HT213254https://support.apple.com/en-us/HT213258https://support.apple.com/kb/HT213675
2022-05-26
Published