First published: Mon May 16 2022(Updated: )
An out-of-bounds read issue was addressed with improved bounds checking. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. Processing a maliciously crafted AppleScript binary may result in unexpected application termination or disclosure of process memory.
Credit: Qi Sun Trend MicroQi Sun Trend MicroYe Zhang @co0py_Cat Baidu SecurityQi Sun Trend MicroYe Zhang @co0py_Cat Baidu Security product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Catalina | ||
Apple macOS Big Sur | <11.6.6 | 11.6.6 |
<12.4 | 12.4 | |
Apple Mac OS X | >=10.15<10.15.7 | |
Apple Mac OS X | =10.15.7 | |
Apple Mac OS X | =10.15.7-security_update_2020 | |
Apple Mac OS X | =10.15.7-security_update_2020-001 | |
Apple Mac OS X | =10.15.7-security_update_2020-005 | |
Apple Mac OS X | =10.15.7-security_update_2020-007 | |
Apple Mac OS X | =10.15.7-security_update_2021-001 | |
Apple Mac OS X | =10.15.7-security_update_2021-002 | |
Apple Mac OS X | =10.15.7-security_update_2021-003 | |
Apple Mac OS X | =10.15.7-security_update_2021-006 | |
Apple Mac OS X | =10.15.7-security_update_2021-007 | |
Apple Mac OS X | =10.15.7-security_update_2021-008 | |
Apple Mac OS X | =10.15.7-security_update_2022-001 | |
Apple Mac OS X | =10.15.7-security_update_2022-002 | |
Apple Mac OS X | =10.15.7-security_update_2022-003 | |
Apple Mac OS X | =10.15.7-supplemental_update | |
Apple macOS | >=11.0<11.6.6 | |
Apple macOS | >=12.0.0<12.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-26698 refers to an out-of-bounds read vulnerability in AppleScript that has been addressed with improved bounds checking.
CVE-2022-26698 affects Apple's Catalina, macOS Big Sur (up to version 11.6.6), and macOS Monterey (up to version 12.4).
To fix CVE-2022-26698, you should ensure that you are running the latest version of the affected Apple software, such as macOS Big Sur 11.6.6 or macOS Monterey 12.4.
You can find more information about CVE-2022-26698 on the official Apple support page: <a href='https://support.apple.com/en-us/HT213257'>https://support.apple.com/en-us/HT213257</a>.