6.5
CVSSv3

CVE-2022-26726

Published: 26/05/2022 Updated: 07/06/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

This issue was addressed with improved checks. This issue is fixed in Security Update 2022-004 Catalina, watchOS 8.6, macOS Monterey 12.4, macOS Big Sur 11.6.6. An app may be able to capture a user's screen.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x

apple mac os x 10.15.7

apple macos

apple watchos

Vendor Advisories

About Apple security updates For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available Recent releases are listed on the Apple security updates page Apple security documents reference vulnerabilities by CVE-ID&nbsp ...
About Apple security updates For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available Recent releases are listed on the Apple security updates page Apple security documents reference vulnerabilities by CVE-ID&nbsp ...

Github Repositories

TCC Bypass

CVE-2022-26726 Affected Versions As a student, I have limited access to devices in which I can test this vulnerability The versions I have tested so far are MacOS 1231, MacOS 123, MacOS 120, MacOS 10157, and MacOS 1161 The vulnerability works on all the versions tested on So what is the bug? Impact: A malicious application may be able to bypass certain Privacy prefer

TCC Bypass

CVE-2022-26726 Affected Versions As a student, I have limited access to devices in which I can test this vulnerability The versions I have tested so far are MacOS 1231, MacOS 123, MacOS 120, MacOS 10157, and MacOS 1161 The vulnerability works on all the versions tested on So what is the bug? Impact: A malicious application may be able to bypass certain Privacy prefer