First published: Mon May 16 2022(Updated: )
AVEVideoEncoder. An out-of-bounds write issue was addressed with improved bounds checking.
Credit: an anonymous researcher an anonymous researcher an anonymous researcher an anonymous researcher an anonymous researcher an anonymous researcher an anonymous researcher an anonymous researcher an anonymous researcher an anonymous researcher an anonymous researcher an anonymous researcher an anonymous researcher an anonymous researcher an anonymous researcher product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple tvOS | <15.5 | 15.5 |
<12.4 | 12.4 | |
Apple iOS | <15.5 | 15.5 |
Apple iPadOS | <15.5 | 15.5 |
Apple iPadOS | <15.5 | |
Apple iPhone OS | <15.5 | |
Apple macOS | >=12.0<12.4 | |
Apple tvOS | <15.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-26740 is an out-of-bounds write vulnerability in AVEVideoEncoder that has been addressed with improved bounds checking.
CVE-2022-26740 affects Apple tvOS up to version 15.5, macOS Monterey up to version 12.4, Apple iOS up to version 15.5, and Apple iPadOS up to version 15.5.
The severity of CVE-2022-26740 depends on several factors such as the attacker's capabilities and the system's configuration, but since it has been addressed with improved bounds checking, it is recommended to update the affected software to the patched versions.
To fix CVE-2022-26740, you should update the affected software (tvOS, macOS Monterey, iOS, and iPadOS) to the patched versions (15.5 for tvOS and iOS, and 12.4 for macOS Monterey).
You can find more information about CVE-2022-26740 on the Apple support page: [CVE-2022-26740](https://support.apple.com/en-us/HT213254).