First published: Mon May 16 2022(Updated: )
AVEVideoEncoder. An out-of-bounds write issue was addressed with improved bounds checking.
Credit: an anonymous researcher an anonymous researcher an anonymous researcher an anonymous researcher an anonymous researcher an anonymous researcher an anonymous researcher an anonymous researcher an anonymous researcher an anonymous researcher an anonymous researcher an anonymous researcher an anonymous researcher an anonymous researcher an anonymous researcher product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple tvOS | <15.5 | 15.5 |
<12.4 | 12.4 | |
Apple iOS | <15.5 | 15.5 |
Apple iPadOS | <15.5 | 15.5 |
Apple iPadOS | <15.5 | |
Apple iPhone OS | <15.5 | |
Apple macOS | <12.4 | |
Apple tvOS | <15.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-26738 is a vulnerability in AVEVideoEncoder that allows an attacker to perform an out-of-bounds write.
CVE-2022-26738 affects Apple tvOS up to version 15.5, macOS Monterey up to version 12.4, Apple iOS up to version 15.5, and Apple iPadOS up to version 15.5.
CVE-2022-26738 can be exploited by an attacker to perform an out-of-bounds write operation, potentially leading to arbitrary code execution or denial of service.
Yes, Apple has addressed the CVE-2022-26738 vulnerability with improved bounds checking in the affected software versions.
You can find more information about CVE-2022-26738 on the official Apple support website.