Executive brief
A type confusion vulnerability in Apple's WebKit engine allows for arbitrary code execution when processing maliciously crafted web content. The issue was addressed through improved memory handling across multiple Apple operating systems and applications.
Affected products
- Apple iOS Before 12.2
- Apple tvOS Before 12.2
- Apple watchOS Before 5.2
- Apple Safari Before 12.1
- Apple iTunes for Windows Before 12.9.4
- Apple iCloud for Windows Before 7.11
Timeline
- 2019-12-31: disclosed: Initial NVD analysis date
- 2022-05-04: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-05-04: exploited: Confirmed exploited in the wild per CISA KEV entry