Junglewise Threat Intelligence

CVE-2022-22620: Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability

CVE-2022-22620 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-02-11

Technologies: Apple Safari, Cisco IOS, Apple macOS, Apple watchOS, Apple iPadOS, Apple macOS Monterey. Vendors: Apple, Cisco.

Executive brief

Apple WebKit contains a use-after-free vulnerability when processing maliciously crafted web content. Successful exploitation allows for arbitrary code execution on affected iOS, iPadOS, and macOS systems.

Affected products

  • Apple WebKit
  • Apple Safari < 15.3
  • Apple iOS < 15.3.1
  • Apple iPadOS < 15.3.1
  • Apple macOS Monterey 12.0.0 - < 12.2.1

Timeline

  • 2022-02-11: disclosed: Initial publication date
  • 2022-02-11: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-02-11: patched: Fixed in macOS Monterey 12.2.1, iOS 15.3.1, iPadOS 15.3.1, and Safari 15.3
  • 2022-02-11: exploited: Apple reported awareness of active exploitation in the wild

Related threats