First published: Wed Jan 26 2022(Updated: )
An event handler validation issue in the XPC Services API was addressed by removing the service. This issue is fixed in macOS Monterey 12.2. An application may be able to delete files for which it does not have permission.
Credit: Mickey Jin @patch1t Trend Micro product-security@apple.com product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS Monterey | <12.2 | 12.2 |
Apple macOS | >=12.0.0<12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2022-22676.
The title of this vulnerability is 'PackageKit. An event handler validation issue in the XPC Services API was addressed by removing the …'.
The severity of CVE-2022-22676 is medium with a severity value of 5.5.
Versions up to but excluding 12.2 of macOS Monterey are affected by this vulnerability.
The vulnerability in macOS Monterey 12.2 is fixed by addressing the event handler validation issue in the XPC Services API.
An application can delete files for which it does not have permission in macOS Monterey by exploiting this vulnerability.
You can find more information about this vulnerability at 'https://support.apple.com/en-us/HT213054'.