First published: Mon May 16 2022(Updated: )
A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to arbitrary code execution.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple watchOS | <8.6 | 8.6 |
Apple tvOS | <15.5 | 15.5 |
<12.4 | 12.4 | |
Apple iOS | <15.5 | 15.5 |
Apple iPadOS | <15.5 | 15.5 |
Apple Safari | <15.5 | 15.5 |
Apple Safari | <15.5 | |
Apple iPadOS | <15.5 | |
Apple iPhone OS | <15.5 | |
Apple macOS | >=12.0.0<12.4 | |
Apple tvOS | <15.5 | |
Apple watchOS | <8.6 | |
debian/webkit2gtk | 2.36.4-1~deb10u1 2.38.6-0+deb10u1 2.40.5-1~deb11u1 2.42.1-1~deb11u2 2.40.5-1~deb12u1 2.42.1-1~deb12u1 2.42.1-2 | |
debian/wpewebkit | 2.38.6-1~deb11u1 2.38.6-1 2.42.1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-26716 is a memory corruption issue in WebKit that was addressed with improved state management.
CVE-2022-26716 affects Apple Safari versions up to but not including 15.5, Apple watchOS versions up to but not including 8.6, Apple tvOS versions up to but not including 15.5, macOS Monterey versions up to but not including 12.4, Apple iOS versions up to but not including 15.5, and Apple iPadOS versions up to but not including 15.5.
To fix CVE-2022-26716, update your software to the latest version available. For more information, refer to the official Apple security updates.