First published: Mon May 16 2022(Updated: )
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. Processing a maliciously crafted AppleScript binary may result in unexpected application termination or disclosure of process memory.
Credit: Qi Sun Robert Ai Trend MicroQi Sun Trend MicroRobert Ai Trend MicroQi Sun Trend MicroRobert Ai Trend Micro product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Catalina | ||
Apple macOS Big Sur | <11.6.6 | 11.6.6 |
<12.4 | 12.4 | |
Apple Mac OS X | >10.15<10.15.7 | |
Apple Mac OS X | =10.15.7 | |
Apple Mac OS X | =10.15.7-security_update_2020 | |
Apple Mac OS X | =10.15.7-security_update_2020-001 | |
Apple Mac OS X | =10.15.7-security_update_2020-005 | |
Apple Mac OS X | =10.15.7-security_update_2020-007 | |
Apple Mac OS X | =10.15.7-security_update_2021-001 | |
Apple Mac OS X | =10.15.7-security_update_2021-002 | |
Apple Mac OS X | =10.15.7-security_update_2021-003 | |
Apple Mac OS X | =10.15.7-security_update_2021-006 | |
Apple Mac OS X | =10.15.7-security_update_2021-007 | |
Apple Mac OS X | =10.15.7-security_update_2021-008 | |
Apple Mac OS X | =10.15.7-security_update_2022-001 | |
Apple Mac OS X | =10.15.7-security_update_2022-002 | |
Apple Mac OS X | =10.15.7-security_update_2022-003 | |
Apple Mac OS X | =10.15.7-supplemental_update | |
Apple macOS | >=11.0<11.6.6 | |
Apple macOS | >=12.0.0<12.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2022-26697.
The title of the vulnerability is 'AppleScript. An out-of-bounds read was addressed with improved input validation.'
The severity of CVE-2022-26697 is not mentioned in the provided information.
Apple macOS Catalina, Big Sur (up to version 11.6.6), and Monterey (up to version 12.4) are affected by this vulnerability.
To fix the CVE-2022-26697 vulnerability, update your Apple macOS to the latest available version.