cbcvebase.
CVE-2022-22620
published 2022-03-18

CVE-2022-22620: A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3…

PriorityP188high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-02-25
Exploited in the wild
EPSS
16.34%
96.6th percentile
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

Affected

12 ranges
VendorProductVersion rangeFixed in
appleios_15.3.1_and_ipados
appleipados< 15.3.115.3.1
appleiphone_os< 15.3.115.3.1
applemacos>= 12.0.0 < 12.2.112.2.1
applemacos>= unspecified < 12.212.2
applemacos>= unspecified < 15.315.3
applemacos_monterey
applesafari< 15.315.3
applesafari
applesafari>= unspecified < 15.315.3
debianwebkit2gtk< webkit2gtk 2.34.6-1 (bookworm)webkit2gtk 2.34.6-1 (bookworm)
debianwpewebkit< webkit2gtk 2.34.6-1 (bookworm)webkit2gtk 2.34.6-1 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2022-22620 is a Use-After-Free vulnerability in WebKit (the browser engine). Detection should focus on exploitation attempts via maliciously crafted web content delivered to Safari, macOS, iOS, or iPadOS WebKit-based browsers.
  • The vulnerability resides specifically in the WebKit component. Monitor WebKit-based browser processes (e.g., Safari) for unexpected crashes, memory corruption signals, or arbitrary code execution following web content processing.
  • This vulnerability was actively exploited in the wild against iPhones, iPads, and Macs. Prioritize detection on unpatched Apple devices running Safari/WebKit versions prior to the fixed releases.
  • ·Fixed Safari versions are 15.3 (build 16612.4.9.1.8 and 15612.4.9.1.8); devices running earlier builds remain vulnerable. Use version/build detection to identify unpatched endpoints.
  • ·On Debian-based Linux systems (webkit2gtk), the vulnerability is resolved in version 2.34.6-1 and backports. Hosts running earlier webkit2gtk versions should be flagged.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.