8.8
CVSSv3

CVE-2022-42856

Published: 15/12/2022 Updated: 09/01/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8

Vulnerability Summary

A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1..

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple tvos

apple ipados

apple iphone os

apple macos

apple safari

Vendor Advisories

Synopsis Important: webkit2gtk3 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for webkit2gtk3 is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as h ...
Synopsis Important: webkit2gtk3 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for webkit2gtk3 is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as h ...
Description<!----> This CVE is under investigation by Red Hat Product Security ...

Github Repositories

CVE-2022-42856 A type confusion issue was addressed with improved state handling This issue is fixed in Safari 162, tvOS 162, macOS Ventura 131, iOS 1572 and iPadOS 1572, iOS 1612 Processing maliciously crafted web content may lead to arbitrary code execution Apple is aware of a report that this issue may have been actively exploited against versions of iOS released

Recent Articles

Apple emits emergency patch for older iPhones after snoops pounce on WebKit hole
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources Also: Yay for Data Privacy Day!

Apple has issued an emergency patch for older kit to fix a WebKit security flaw that Cupertino warns is under active attack.
On Monday, Apple released iOS 12.5.7 for iPhone 5s, iPhone 6, iPhone 6 Plus, iPad Air, iPad mini 2, iPad mini 3, and sixth-generation iPod touch. It also updated iOS and iPadOS 15 and 16, but it appears that, at least as of now, attackers are only going after devices running the very-old iOS 12.
If you have one of these older devices, we'd suggest updating to t...