CVE-2022-22620
published 2022-03-18CVE-2022-22620: A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3…
PriorityP188high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-02-25
Exploited in the wild
EPSS
16.34%
96.6th percentile
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_15.3.1_and_ipados | — | — |
| apple | ipados | < 15.3.1 | 15.3.1 |
| apple | iphone_os | < 15.3.1 | 15.3.1 |
| apple | macos | >= 12.0.0 < 12.2.1 | 12.2.1 |
| apple | macos | >= unspecified < 12.2 | 12.2 |
| apple | macos | >= unspecified < 15.3 | 15.3 |
| apple | macos_monterey | — | — |
| apple | safari | < 15.3 | 15.3 |
| apple | safari | — | — |
| apple | safari | >= unspecified < 15.3 | 15.3 |
| debian | webkit2gtk | < webkit2gtk 2.34.6-1 (bookworm) | webkit2gtk 2.34.6-1 (bookworm) |
| debian | wpewebkit | < webkit2gtk 2.34.6-1 (bookworm) | webkit2gtk 2.34.6-1 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2022-22620 is a Use-After-Free vulnerability in WebKit (the browser engine). Detection should focus on exploitation attempts via maliciously crafted web content delivered to Safari, macOS, iOS, or iPadOS WebKit-based browsers. ↗
- →The vulnerability resides specifically in the WebKit component. Monitor WebKit-based browser processes (e.g., Safari) for unexpected crashes, memory corruption signals, or arbitrary code execution following web content processing. ↗
- →This vulnerability was actively exploited in the wild against iPhones, iPads, and Macs. Prioritize detection on unpatched Apple devices running Safari/WebKit versions prior to the fixed releases. ↗
- ·Fixed Safari versions are 15.3 (build 16612.4.9.1.8 and 15612.4.9.1.8); devices running earlier builds remain vulnerable. Use version/build detection to identify unpatched endpoints. ↗
- ·On Debian-based Linux systems (webkit2gtk), the vulnerability is resolved in version 2.34.6-1 and backports. Hosts running earlier webkit2gtk versions should be flagged. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
webkitgtk: maliciously crafted web content may lead to arbitrary code execution due to use after free
vendor_redhat·2022-02-17·CVSS 8.8
CVE-2022-22620 [HIGH] CWE-416 webkitgtk: maliciously crafted web content may lead to arbitrary code execution due to use after free
webkitgtk: maliciously crafted web content may lead to arbitrary code execution due to use after free
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
A use-after-free vulnerability was found in WebKitGTK. The vulnerability occurs when processing HTML content in WebKit. This flaw allows a remote attacker to trick the victim into opening a specially crafted web page, triggering a use-after-free error and leading to the execution of arbitrary code on the system.
Package: webkit2gtk3 (Red
CISA
Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability
cisa·2022-02-11·CVSS 8.8
CVE-2022-22620 [HIGH] CWE-416 Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability
Vulnerability: Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability
Affected: Apple iOS, iPadOS, and macOS
Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-22620
Remediation Due Date: 2022-02-25
Apple
CVE-2022-22620: Safari 15.3
vendor_apple·2022-02-10·CVSS 8.8
CVE-2022-22620 [HIGH] CVE-2022-22620: Safari 15.3
Apple Security Update: About the security content of Safari 15.3
Product: Safari
Version: 15.3
CVE: CVE-2022-22620
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Description: A use after free issue was addressed with improved memory management.
Apple
CVE-2022-22620: macOS Monterey 12.2.1
vendor_apple·2022-02-10·CVSS 8.8
CVE-2022-22620 [HIGH] CVE-2022-22620: macOS Monterey 12.2.1
Apple Security Update: About the security content of macOS Monterey 12.2.1
Product: macOS Monterey
Version: 12.2.1
CVE: CVE-2022-22620
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Description: A use after free issue was addressed with improved memory management.
Apple
CVE-2022-22620: iOS 15.3.1 and iPadOS 15.3.1
vendor_apple·2022-02-10·CVSS 8.8
CVE-2022-22620 [HIGH] CVE-2022-22620: iOS 15.3.1 and iPadOS 15.3.1
Apple Security Update: About the security content of iOS 15.3.1 and iPadOS 15.3.1
Product: iOS 15.3.1 and iPadOS
Version: 15.3.1
CVE: CVE-2022-22620
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Description: A use after free issue was addressed with improved memory management.
Debian
CVE-2022-22620: webkit2gtk - A use after free issue was addressed with improved memory management. This issue...
vendor_debian·2022·CVSS 8.8
CVE-2022-22620 [HIGH] CVE-2022-22620: webkit2gtk - A use after free issue was addressed with improved memory management. This issue...
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
Scope: local
bookworm: resolved (fixed in 2.34.6-1)
bullseye: resolved (fixed in 2.34.6-1~deb11u1)
forky: resolved (fixed in 2.34.6-1)
sid: resolved (fixed in 2.34.6-1)
trixie: resolved (fixed in 2.34.6-1)
Project0
2022 0-day In-the-Wild Exploitation…so far - Project Zero
project_zero·2022-06-01·CVSS 8.8
CVE-2016-5128 [HIGH] 2022 0-day In-the-Wild Exploitation…so far - Project Zero
Posted by Maddie Stone, Google Project Zero
This blog post is an overview of a talk, “ 0-day In-the-Wild Exploitation in 2022…so far”, that I gave at the FIRST conference in June 2022. The slides are available here.
For the last three years, we’ve published annual year-in-review reports of 0-days found exploited in the wild. The most recent of these reports is the 2021 Year in Review report, which we published just a few months ago in April. While we plan to stick with that annual cadence, we’re publishing a little bonus report today looking at the in-the-wild 0-days detected and disclosed in the first half of 2022.
As of June 15, 2022, there have been 18 0-days detected and disclosed as exploited in-the-wild in 2022. When we analyzed those 0-days, we found that at least nin
Project0
An Autopsy on a Zombie In-the-Wild 0-day - Project Zero
project_zero·2022-06-01·CVSS 8.8
CVE-2022-22600 [HIGH] An Autopsy on a Zombie In-the-Wild 0-day - Project Zero
Posted by Maddie Stone, Google Project Zero
Whenever there’s a new in-the-wild 0-day disclosed, I’m very interested in understanding the root cause of the bug. This allows us to then understand if it was fully fixed, look for variants, and brainstorm new mitigations. This blog is the story of a “zombie” Safari 0-day and how it came back from the dead to be disclosed as exploited in-the-wild in 2022. CVE-2022-22620 was initially fixed in 2013, reintroduced in 2016, and then disclosed as exploited in-the-wild in 2022. If you’re interested in the full root cause analysis for CVE-2022-22620, we’ve published it here.
In the 2020 Year in Review of 0-days exploited in the wild, I wrote how 25% of all 0-days detected and disclosed as exploited in-the-wild in 2020 were variants of previou
GHSA
GHSA-2886-x646-53fj: A use after free issue was addressed with improved memory management
ghsa_unreviewed·2022-03-19
CVE-2022-22620 [HIGH] CWE-416 GHSA-2886-x646-53fj: A use after free issue was addressed with improved memory management
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
OSV
CVE-2022-22620: A use after free issue was addressed with improved memory management
osv·2022-03-18·CVSS 8.8
CVE-2022-22620 [HIGH] CVE-2022-22620: A use after free issue was addressed with improved memory management
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
VulnCheck
Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability
vulncheck·2022·CVSS 8.8
CVE-2022-22620 [HIGH] CWE-416 Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability
Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability
Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Affected: Apple iOS, iPadOS, and macOS
Required Action: Apply updates per vendor instructions.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://support.apple.com/kb/HT213091; https://support.apple.com/kb/HT213092; https://support.apple.com/kb/HT213093; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.jso
Project0
Project Zero RCA: CVE-2022-22620: Use-after-free in Safari
project_zero·CVSS 8.8
CVE-2022-22620 [HIGH] Project Zero RCA: CVE-2022-22620: Use-after-free in Safari
# CVE-2022-22620: Use-after-free in Safari
*Maddie Stone*
## The Basics
**Disclosure or Patch Date:** 10 February 2022
**Product:** Apple Safari/WebKit
**Advisory:** https://support.apple.com/en-us/HT213093
**Affected Versions:** Safari 15.3, iOS 15.3, macOS 12.2 and earlier
**First Patched Version:** Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8), iOS 15.3.1, macOS 12.2.1
**Issue/Bug Report:** https://bugs.webkit.org/show_bug.cgi?id=235551
**Patch CL:** https://github.com/WebKit/WebKit/commit/486816dc355c19f1de1b8056f85d0bbf7084dd6e
**Bug-Introducing CL:** https://github.com/WebKit/WebKit/commit/aa31b6b4d09b09acdf1cec11f2f7f35bd362dd0e
**Reporter(s):** Anonymous
## The Code
**Proof-of-concept:**
```javascript
input = document.body.appendChild(document.createElement("input")
No detection rules found.
No public exploits indexed.
Checkpoint
14th February– Threat Intelligence Report
blogs_checkpoint·2022-02-14
CVE-2022-22620 14th February– Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 14th February– Threat Intelligence Report
For the latest discoveries in cyber research for the week of 14th February, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
APT group called “ModifiedElephant” has been operating since 2012, targeting human rights activists, academics and lawyers in India with the goal of planting incriminating digital evidences using spear phishing methods.
Researchers have discovered that North Korean APT group Kimsuky has been active in campaigns involvin
arXiv
S2malloc: Statistically Secure Allocator for Use-After-Free Protection And More
arxiv_fulltext·2024-05-29
S2malloc: Statistically Secure Allocator for Use-After-Free Protection And More
: Statistically Secure Allocator for Use-After-Free Protection And More
Ruizhe Wang0009-0001-5607-3917
Meng Xu0009-0001-6364-4837
N. Asokan0000-0002-5093-9871
R. Wang et al.
University of Waterloo
\ruizhe.wang, meng.xu.cs\@uwaterloo.ca [email protected]
## Abstract
Attacks on heap memory, encompassing
memory overflow,
double and invalid free,
use-after-free (UAF),
and
various heap spraying techniques
are ever-increasing.
Existing entropy-based secure
memory allocators provide statistical defenses
against virtually all of these attack vectors.
Although they claim protections against UAF attacks,
their designs are not tailored to detect
(failed) attempts.
Consequently,
to beat this entropy-based protection,
an attacker can simply launch the same attack repeatedly
with the potential use
https://security.gentoo.org/glsa/202208-39https://support.apple.com/en-us/HT213091https://support.apple.com/en-us/HT213092https://support.apple.com/en-us/HT213093https://security.gentoo.org/glsa/202208-39https://support.apple.com/en-us/HT213091https://support.apple.com/en-us/HT213092https://support.apple.com/en-us/HT213093https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22620
2022-03-18
Published
2022-02-11
Added to CISA KEV
Exploited in the wild