CVE-2022-26697: Apple Mac OS X

High severity, CVSS 7.1. EPSS: 1.1% chance of exploitation in the next 30 days.

An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. Processing a maliciously crafted AppleScript binary may result in unexpected application termination or disclosure of process memory.

Affected products

  • Apple Mac OS X: after 10.15, before 10.15.7 (fixed in 10.15.7); version 10.15.7 only
  • Apple macOS: from 11.0, before 11.6.6 (fixed in 11.6.6); from 12.0.0, before 12.4 (fixed in 12.4)

Published 2022-05-26. Last modified 2026-06-17.