CVE-2022-26696 is a high-severity sandbox escape vulnerability affecting macOS Monterey versions prior to 12.4, allowing a sandboxed process to bypass security restrictions due to insufficient environment sanitization. With a CVSS score of 8.8, this local vulnerability is easily exploitable and can lead to high impact on confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, a Proof-of-Concept (PoC) exploit has been published, and it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.0.0, < 12.4CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
< 12.4CPE match | cpe:2.3:a:apple:macos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.