CVE-2022-26765

Severity CVSS v4.0:
Pending analysis
Type:
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
26/05/2022
Last modified:
30/05/2025

Description

A race condition was addressed with improved state handling. This issue is fixed in watchOS 8.6, tvOS 15.5, macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* 15.5 (excluding)
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* 15.5 (excluding)
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* 12.0 (including) 12.4 (excluding)
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* 15.5 (excluding)
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* 8.6 (excluding)