CVE-2022-26711
CRITICALiTunes < 12.12.4 - Remote Code Execution via Integer Overflow
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-26711. PoCs published by xpcmdshell.
AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2022-26711, an integer overflow vulnerability in Apple's ImageIO framework when parsing WebP images. The exploit demonstrates how a maliciously crafted WebP image can lead to arbitrary code execution in applications using ImageIO.
Description
An integer overflow issue was addressed with improved input validation. This issue is fixed in tvOS 15.5, iTunes 12.12.4 for Windows, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
Exploits (1)
This repository contains a proof-of-concept exploit for CVE-2022-26711, an integer overflow vulnerability in Apple's ImageIO framework when parsing WebP images. The exploit demonstrates how a maliciously crafted WebP image can lead to arbitrary code execution in applications using ImageIO.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H