A use after free vulnerability was found in WebKitGTK allowing an malicious user to perform remote code execution using maliciously crafted web content.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
apple macos |
||
apple ipados |
||
apple safari |
||
apple iphone os |
Get our weekly newsletter Flaw imperils Safari – and every iOS browser because of Cupertino's T&Cs
Apple on Thursday patched a zero-day security vulnerability in its WebKit browser engine, issuing updates for iOS, iPadOS, and macOS. Its Safari browser, based on WebKit, received the security update separately for instances where it is being used with an older version of macOS, like Big Sur. Apple's tvOS was also refreshed, but without the security fix. The updates – iOS 15.3.1, iPadOS 15.3.1, and macOS Monterey 12.2.1 – address CVE-2022-22620, reported to Apple by an anonymous researcher. ...
Topics Security Off-Prem On-Prem Software Offbeat Vendor Voice Vendor Voice Resources Fixed in 2013, reinstated in 2016, exploited in the wild this year
A security flaw in Apple's Safari web browser that was patched nine years ago was exploited in the wild again some months ago – a perfect example of a "zombie" vulnerability. That's a bug that's been patched, but for whatever reason can be abused all over again on up-to-date systems and devices – or a bug closely related to a patched one. In a write-up this month, Maddie Stone, a top researcher on Google's Project Zero team, shared details of a Safari vulnerability that folks realized in Jan...