CVE-2022-26717

HIGH

iTunes < 12.12.4 - Use-After-Free

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2022-26717. PoCs published by theori-io, Theori-lO.

AI-analyzed exploit summary This repository contains a README describing CVE-2022-26717, a Safari WebGL use-after-free vulnerability. No exploit code is present, only credits and patch information.

Description

A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, Safari 15.5, iTunes 12.12.4 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.

Exploits (2)

nomisec WRITEUP 56 stars
by theori-io · poc
https://github.com/theori-io/CVE-2022-26717-Safari-WebGL-Exploit

This repository contains a README describing CVE-2022-26717, a Safari WebGL use-after-free vulnerability. No exploit code is present, only credits and patch information.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Theoretical
Reliability
Theoretical
Target: Apple Safari (WebGL implementation)
No auth needed
Prerequisites: Victim must visit a malicious webpage using Safari
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec STUB
by Theori-lO · poc
https://github.com/Theori-lO/CVE-2022-26717-Safari-WebGL-Exploit

The repository contains only a README with minimal information about CVE-2022-26717, a Safari WebGL use-after-free vulnerability, but no exploit code or technical details.

Classification
Stub 90%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: Apple Safari (WebGL)
No auth needed
Prerequisites: none
devstral-2 · analyzed Apr 30, 2026 Full analysis →

References (6)

Core 6
Core References
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213253
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213254
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213257
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213258
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213259
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213260

Scores

CVSS v3 8.8
EPSS 0.0142
EPSS Percentile 69.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-416
Status published
Products (7)
apple/ipados < 15.5
apple/iphone_os < 15.5
apple/itunes < 12.12.4
apple/macos 12.0.0 - 12.4
apple/safari < 15.5
apple/tvos < 15.5
apple/watchos < 8.6
Published Nov 01, 2022
Tracked Since Feb 18, 2026