CVE-2022-22620: Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
Other sources
A use after free when processing maliciously crafted web content may lead to arbitrary code execution.
Reference:
https://webkitgtk.org/security/WSA-2022-0003.html
— Red Hat
Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
— CISA
WebKit. A use after free issue was addressed with improved memory management.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
macOSto a version that resolves this vulnerability.Fixed in 12.2.1 - Upgrade
Upgrade
Safarito a version that resolves this vulnerability.Fixed in 15.3 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 15.3.1 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 15.3.1 - Upgrade
Upgrade
redhat/webkit2gtk3to a version that resolves this vulnerability.Fixed in 2.34.6
Event History
Frequently Asked Questions
What is CVE-2022-22620?
CVE-2022-22620 is a remote code execution vulnerability in Apple Webkit that affects iOS, iPadOS, and macOS.
Which software is affected by CVE-2022-22620?
CVE-2022-22620 affects Apple Webkit, iOS, iPadOS, macOS Monterey, and Safari.
What is the severity of CVE-2022-22620?
The severity of CVE-2022-22620 is not mentioned in the provided information.
How can I fix CVE-2022-22620?
To fix CVE-2022-22620, it is recommended to update to the latest version of Apple Webkit, iOS, iPadOS, macOS Monterey, and Safari.
Where can I find more information about CVE-2022-22620?
More information about CVE-2022-22620 can be found in the references provided: [Reference 1](https://support.apple.com/en-us/HT213093), [Reference 2](https://support.apple.com/en-us/HT213092), [Reference 3](https://support.apple.com/en-us/HT213091).