CVE-2022-26706Apple Watchos vulnerability

8 documents4 sources
Severity
5.5MEDIUMNVD
EPSS
1.2%
top 20.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 26
Latest updateJul 13

Description

An access issue was addressed with additional sandbox restrictions on third-party applications. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. A sandboxed process may be able to circumvent sandbox restrictions.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages11 packages

NVDapple/macos11.011.6.6+1
Appleapple/macos_big_sur11.6.6
NVDapple/tvos< 15.5
NVDapple/ipados< 15.5

🔴Vulnerability Details

1
GHSA
GHSA-6hwh-28c3-73r8: An access issue was addressed with additional sandbox restrictions on third-party applications2022-05-27

📋Vendor Advisories

5
Apple
CVE-2022-26706: macOS Monterey 12.42022-05-16
Apple
CVE-2022-26706: macOS Big Sur 11.6.62022-05-16
Apple
CVE-2022-26706: tvOS 15.52022-05-16
Apple
CVE-2022-26706: iOS 15.5 and iPadOS 15.52022-05-16
Apple
CVE-2022-26706: watchOS 8.62022-05-16

🕵️Threat Intelligence

1
Microsoft
Uncovering a macOS App Sandbox escape vulnerability: A deep dive into CVE-2022-267062022-07-13