First published: Mon May 16 2022(Updated: )
A validation issue existed in the handling of symlinks and was addressed with improved validation of symlinks. This issue is fixed in macOS Monterey 12.4. An app may be able to gain elevated privileges.
Credit: Gergely Kalman @gergely_kalman Mandiant MandiantJoshua Mason MandiantGergely Kalman @gergely_kalman Mandiant MandiantJoshua Mason MandiantJoshua Mason MandiantJoshua Mason Mandiant product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Catalina | ||
Apple Mac OS X | >=10.15<10.15.7 | |
Apple Mac OS X | =10.15.7 | |
Apple Mac OS X | =10.15.7-security_update_2020 | |
Apple Mac OS X | =10.15.7-security_update_2020-001 | |
Apple Mac OS X | =10.15.7-security_update_2020-005 | |
Apple Mac OS X | =10.15.7-security_update_2020-007 | |
Apple Mac OS X | =10.15.7-security_update_2021-001 | |
Apple Mac OS X | =10.15.7-security_update_2021-002 | |
Apple Mac OS X | =10.15.7-security_update_2021-003 | |
Apple Mac OS X | =10.15.7-security_update_2021-004 | |
Apple Mac OS X | =10.15.7-security_update_2021-005 | |
Apple Mac OS X | =10.15.7-security_update_2021-006 | |
Apple Mac OS X | =10.15.7-security_update_2021-007 | |
Apple Mac OS X | =10.15.7-security_update_2021-008 | |
Apple Mac OS X | =10.15.7-security_update_2022-001 | |
Apple Mac OS X | =10.15.7-security_update_2022-002 | |
Apple Mac OS X | =10.15.7-security_update_2022-003 | |
Apple Mac OS X | =10.15.7-security_update_2022-004 | |
Apple macOS | >=11.0<11.6.8 | |
Apple macOS | >=12.0.0<12.4 | |
Apple macOS Big Sur | <11.6.8 | 11.6.8 |
Apple iOS | <15.5 | 15.5 |
Apple iPadOS | <15.5 | 15.5 |
<12.4 | 12.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-26704 is a vulnerability related to a validation issue in the handling of symlinks in Apple Spotlight.
CVE-2022-26704 affects Apple software including macOS Big Sur (up to version 11.6.8) and macOS Monterey (up to version 12.4).
The severity of CVE-2022-26704 has not been specified.
To fix CVE-2022-26704, update your Apple software to the recommended versions: macOS Big Sur 11.6.8 or macOS Monterey 12.4.
More information about CVE-2022-26704 can be found on the Apple support page: [https://support.apple.com/en-us/HT213257](https://support.apple.com/en-us/HT213257)