CVE-2022-22620
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1,...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- January 05, 2022
- Published Date
- March 18, 2022
- Last Updated
- January 29, 2025
- Vendor
- Apple
- Product
- Safari (v and ), macOS
- Description
- A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
CVSS Scores
CVSS v3.1
8.8 - HIGH
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0
6.8 -
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
SSVC Information
- Exploitation
- active
- Technical Impact
- total
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2022-02-11 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
springsec/CVE-2022-22620
Type: github • Created: 2022-08-04 07:11:39 UTC • Stars: 7
Webkit (Safari) - Exploit
kmeps4/CVE-2022-22620
Type: github • Created: 2022-06-14 22:08:14 UTC • Stars: 3
CVE-2022-22620: Use-after-free in Safari