5.5
CVSSv3

CVE-2022-26766

Published: 26/05/2022 Updated: 08/06/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A certificate parsing issue was addressed with improved checks. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. A malicious app may be able to bypass signature validation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x

apple mac os x 10.15.7

apple ipados

apple iphone os

apple macos

apple tvos

apple watchos

Vendor Advisories

About Apple security updates For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available Recent releases are listed on the Apple security updates page Apple security documents reference vulnerabilities by CVE-ID&nbsp ...
About Apple security updates For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available Recent releases are listed on the Apple security updates page Apple security documents reference vulnerabilities by CVE-ID&nbsp ...
About Apple security updates For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available Recent releases are listed on the Apple security updates page Apple security documents reference vulnerabilities by CVE-ID&nbsp ...

Github Repositories

Proof-of-concept for CVE-2022-26766 on macOS 12.3.1

Demo for Linus Henze's CoreTrust bug (CVE-2022-26766, CoreTrust allows any root certificate) See worthdoingbadlycom/coretrust/ for usage

Fucking Simple Untether for iOS 15-17

___________ __ __ __ __ __ / ____/ ___// / / /___ / /____ / /_/ /_ ___ _____ / /_ \__ \/ / / / __ \/ __/ _ \/ __/ __ \/ _ \/ ___/ / __/ ___/ / /_/ / / / / /_/ __/ /_/ / / / __/ / /_/ /____/\____/_/ /_/\__/\___/\__/_/ /_/\___/_/ by Ingan121 Fucking Simple Untethere