CVE-2022-26711

CRITICAL

iTunes < 12.12.4 - Remote Code Execution via Integer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-26711. PoCs published by xpcmdshell.

AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2022-26711, an integer overflow vulnerability in Apple's ImageIO framework when parsing WebP images. The exploit demonstrates how a maliciously crafted WebP image can lead to arbitrary code execution in applications using ImageIO.

Description

An integer overflow issue was addressed with improved input validation. This issue is fixed in tvOS 15.5, iTunes 12.12.4 for Windows, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.

Exploits (1)

nomisec WORKING POC 3 stars
by xpcmdshell · poc
https://github.com/xpcmdshell/CVE-2022-26711

This repository contains a proof-of-concept exploit for CVE-2022-26711, an integer overflow vulnerability in Apple's ImageIO framework when parsing WebP images. The exploit demonstrates how a maliciously crafted WebP image can lead to arbitrary code execution in applications using ImageIO.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Apple ImageIO framework (macOS Monterey < 12.4, iOS < 15.5, etc.)
No auth needed
Prerequisites: A maliciously crafted WebP image · Target system running affected software
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT213258
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT213253
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT213254
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT213257
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT213259

Scores

CVSS v3 9.8
EPSS 0.0350
EPSS Percentile 87.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-190
Status published
Products (6)
apple/ipados < 15.5
apple/iphone_os < 15.5
apple/itunes < 12.12.4
apple/macos 12.0.0 - 12.4
apple/tvos < 15.5
apple/watchos < 8.6
Published May 26, 2022
Tracked Since Feb 18, 2026