CVE-2022-26766Exploit(apple / ipados)

LOWCVSS 5.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apple ipados systems immediately
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: High priority (within 72h)

NVD description

A certificate parsing issue was addressed with improved checks. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. A malicious app may be able to bypass signature validation.

3.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • mac_os_x
  • macos

Threat summary

  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-07); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
ipadosiphone_osmac_os_xmacostvoswatchos

1 version affected across 6 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-07: 1Mentions · 2026-02-08: 1Exploit Tool / Code · 2026-02-07: 1Patch / Workaround · 2026-02-07: 1Technical Details · 2026-02-07: 102-0702-08
Signal classification2 categories
Exploit
150.0%
General
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-071
Exploit1
2026-02-081
General1
Full discourse2 posts
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2025-55241 2 - CVE-2022-26766 3 - CVE-2026-1731 4 - CVE-2026-20817 5 - CVE-2026-21509 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    A list of five trending CVEs is provided without any additional detail.

    00010252
    1.7K followersView on X
  • Grok@grok
    Exploit

    TrollStore هو أداة تسمح بتثبيت تطبيقات IPA دائمًا على iOS بدون جيلبريك كامل، مستغلة ثغرات في CoreTrust (CVE-2022-26766 للإصدار 1، وCVE-2023-41991 للإصدار 2). يدعم إصدارات من 14.0 إلى 17.0، مع طرق تثبيت مثل TrollInstallerX وTrollRestore عبر الاستعادة. آبل أغلقت الثغرات، ومع حمايات جديدة مثل SPTM، تكرارها صعب. يوازن بين الحرية والأمان.

    Post summary

    TrollStore exploits CoreTrust CVEs (CVE‑2022‑26766 and CVE‑2023‑41991) to install IPA apps without a full jailbreak, but Apple has since patched the flaws, making repeat exploitation difficult.

    00000263
    8.1M followersView on X
CPE platform detail19 entries

19 of 19 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemac_os_x---
OSapplemac_os_x10.15.7--
OSapplemac_os_x10.15.7--
OSapplemac_os_x10.15.7--
OSapplemac_os_x10.15.7--
OSapplemac_os_x10.15.7--
OSapplemac_os_x10.15.7--
OSapplemac_os_x10.15.7--
OSapplemac_os_x10.15.7--
OSapplemac_os_x10.15.7--
OSapplemac_os_x10.15.7--
OSapplemac_os_x10.15.7--
OSapplemac_os_x10.15.7--
OSapplemac_os_x10.15.7--
OSapplemacos---
OSappletvos---
OSapplewatchos---

Explore more