Junglewise Threat Intelligence

CVE-2022-42856: Apple iOS Type Confusion Vulnerability

CVE-2022-42856 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-12-14

Technologies: Cisco IOS, Apple macOS, Apple Safari, Apple watchOS, Apple Tvos, Apple macOS Ventura, Apple iPadOS. Vendors: Cisco, Apple.

Executive brief

A type confusion vulnerability in Apple's WebKit engine allows for arbitrary code execution when processing maliciously crafted web content. The issue was addressed through improved state handling across multiple Apple operating systems and the Safari browser.

Affected products

  • Apple iOS before 15.7.2, 16.0 to 16.1.2
  • Apple iPadOS before 15.7.2
  • Apple macOS Ventura before 13.1
  • Apple tvOS before 16.2
  • Apple Safari before 16.2

Timeline

  • 2022-12-14: disclosed: Initial publication and CISA KEV addition
  • 2022-12-14: kev added
  • 2022-12-14: patched: Fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2, iPadOS 15.7.2, and iOS 16.1.2
  • exploited: Apple reported awareness of active exploitation against versions of iOS released before iOS 15.1.

Related threats