CVE-2022-26706
published 2022-05-26CVE-2022-26706: An access issue was addressed with additional sandbox restrictions on third-party applications. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5…
PriorityP430medium5.5CVSS 3.1
AVLACLPRNUIRSUCNIHAN
EPSS
7.49%
93.8th percentile
An access issue was addressed with additional sandbox restrictions on third-party applications. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. A sandboxed process may be able to circumvent sandbox restrictions.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_15.5_and_ipados | — | — |
| apple | ipados | < 15.5 | 15.5 |
| apple | iphone_os | < 15.5 | 15.5 |
| apple | macos | >= 11.0 < 11.6.6 | 11.6.6 |
| apple | macos | >= 12.0.0 < 12.4 | 12.4 |
| apple | macos_big_sur | — | — |
| apple | macos_monterey | — | — |
| apple | tvos | < 15.5 | 15.5 |
| apple | tvos | — | — |
| apple | watchos | < 8.6 | 8.6 |
| apple | watchos | — | — |
| apple | watchos | >= unspecified < 8.6 | 8.6 |
| apple | watchos | >= unspecified < 15.5 | 15.5 |
| apple | watchos | >= unspecified < 11.6 | 11.6 |
| apple | watchos | >= unspecified < 12.4 | 12.4 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6hwh-28c3-73r8: An access issue was addressed with additional sandbox restrictions on third-party applications
ghsa_unreviewed·2022-05-27
CVE-2022-26706 [MEDIUM] GHSA-6hwh-28c3-73r8: An access issue was addressed with additional sandbox restrictions on third-party applications
An access issue was addressed with additional sandbox restrictions on third-party applications. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. A sandboxed process may be able to circumvent sandbox restrictions.
Apple
CVE-2022-26706: macOS Monterey 12.4
vendor_apple·2022-05-16·CVSS 5.5
CVE-2022-26706 [MEDIUM] CVE-2022-26706: macOS Monterey 12.4
Apple Security Update: About the security content of macOS Monterey 12.4
Product: macOS Monterey
Version: 12.4
CVE: CVE-2022-26706
Component: LaunchServices
Impact: A sandboxed process may be able to circumvent sandbox restrictions
Description: An access issue was addressed with additional sandbox restrictions on third-party applications.
Apple
CVE-2022-26706: macOS Big Sur 11.6.6
vendor_apple·2022-05-16·CVSS 5.5
CVE-2022-26706 [MEDIUM] CVE-2022-26706: macOS Big Sur 11.6.6
Apple Security Update: About the security content of macOS Big Sur 11.6.6
Product: macOS Big Sur
Version: 11.6.6
CVE: CVE-2022-26706
Component: LaunchServices
Impact: A sandboxed process may be able to circumvent sandbox restrictions
Description: An access issue was addressed with additional sandbox restrictions on third-party applications.
Apple
CVE-2022-26706: tvOS 15.5
vendor_apple·2022-05-16·CVSS 5.5
CVE-2022-26706 [MEDIUM] CVE-2022-26706: tvOS 15.5
Apple Security Update: About the security content of tvOS 15.5
Product: tvOS
Version: 15.5
CVE: CVE-2022-26706
Component: LaunchServices
Impact: A sandboxed process may be able to circumvent sandbox restrictions
Description: An access issue was addressed with additional sandbox restrictions on third-party applications.
Apple
CVE-2022-26706: iOS 15.5 and iPadOS 15.5
vendor_apple·2022-05-16·CVSS 5.5
CVE-2022-26706 [MEDIUM] CVE-2022-26706: iOS 15.5 and iPadOS 15.5
Apple Security Update: About the security content of iOS 15.5 and iPadOS 15.5
Product: iOS 15.5 and iPadOS
Version: 15.5
CVE: CVE-2022-26706
Component: LaunchServices
Impact: A sandboxed process may be able to circumvent sandbox restrictions
Description: An access issue was addressed with additional sandbox restrictions on third-party applications.
Apple
CVE-2022-26706: watchOS 8.6
vendor_apple·2022-05-16·CVSS 5.5
CVE-2022-26706 [MEDIUM] CVE-2022-26706: watchOS 8.6
Apple Security Update: About the security content of watchOS 8.6
Product: watchOS
Version: 8.6
CVE: CVE-2022-26706
Component: LaunchServices
Impact: A sandboxed process may be able to circumvent sandbox restrictions
Description: An access issue was addressed with additional sandbox restrictions on third-party applications.
No detection rules found.
No public exploits indexed.
Checkpoint
18th July – Threat Intelligence Report
blogs_checkpoint·2022-07-18
CVE-2022-2033 18th July – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 18th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 18th July, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
A callback phishing campaign has been observed targeting corporate networks while impersonating known cybersecurity companies – the emails mention an alleged threat in the target’s network, asking them to call the company and let them in the network to investigate. Some suggest the operation is done by the Quantum ransomware ga
Microsoft
Uncovering a macOS App Sandbox escape vulnerability: A deep dive into CVE-2022-26706
blogs_microsoft·2022-07-13·CVSS 5.5
[MEDIUM] Uncovering a macOS App Sandbox escape vulnerability: A deep dive into CVE-2022-26706
Research
July 13, 2022
## Related posts
April 22, 2024
October 25, 2023
September 14, 2023
## Get started with Microsoft Security
Protect your people, data, and infrastructure with AI-powered, end-to-end security from Microsoft.
Connect with us on social
Careers
About Microsoft
Company news
Privacy at Microsoft
Investors
Diversity and inclusion
Accessibility
Sustainability
https://support.apple.com/en-us/HT213253https://support.apple.com/en-us/HT213254https://support.apple.com/en-us/HT213256https://support.apple.com/en-us/HT213257https://support.apple.com/en-us/HT213258https://support.apple.com/en-us/HT213253https://support.apple.com/en-us/HT213254https://support.apple.com/en-us/HT213256https://support.apple.com/en-us/HT213257https://support.apple.com/en-us/HT213258
2022-05-26
Published