CVE-2022-26766

A certificate parsing issue was addressed with improved checks. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. A malicious app may be able to bypass signature validation.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.15.7:-:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2020-001:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-001:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-002:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-003:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-004:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-005:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-006:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-007:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-008:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2022-001:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2022-002:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2022-003:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:54

Type Values Removed Values Added
References () https://support.apple.com/en-us/HT213253 - Vendor Advisory () https://support.apple.com/en-us/HT213253 - Vendor Advisory
References () https://support.apple.com/en-us/HT213254 - Vendor Advisory () https://support.apple.com/en-us/HT213254 - Vendor Advisory
References () https://support.apple.com/en-us/HT213255 - Vendor Advisory () https://support.apple.com/en-us/HT213255 - Vendor Advisory
References () https://support.apple.com/en-us/HT213256 - Vendor Advisory () https://support.apple.com/en-us/HT213256 - Vendor Advisory
References () https://support.apple.com/en-us/HT213257 - Vendor Advisory () https://support.apple.com/en-us/HT213257 - Vendor Advisory
References () https://support.apple.com/en-us/HT213258 - Vendor Advisory () https://support.apple.com/en-us/HT213258 - Vendor Advisory

Information

Published : 2022-05-26 20:15

Updated : 2024-11-21 06:54


NVD link : CVE-2022-26766

Mitre link : CVE-2022-26766

CVE.ORG link : CVE-2022-26766


JSON object : View

Products Affected

apple

  • macos
  • mac_os_x
  • watchos
  • iphone_os
  • ipados
  • tvos
CWE
CWE-295

Improper Certificate Validation