cbcvebase.
CVE-2022-42852
published 2022-12-15

CVE-2022-42852: The issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS…

PriorityP180medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
ITWVulnCheck KEV
Exploited in the wild
EPSS
0.94%
57.0th percentile
The issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may result in the disclosure of process memory.

Affected

21 ranges
VendorProductVersion rangeFixed in
appleios_15.7.2_and_ipados
appleios_16.2_and_ipados
appleipados< 15.7.215.7.2
appleipados>= 16.0 < 16.216.2
appleiphone_os< 15.7.215.7.2
appleiphone_os>= 16.0 < 16.216.2
applemacos
applemacos_ventura
applesafari< 16.216.2
applesafari
appletvos< 16.216.2
appletvos>= unspecified < 16.216.2
appletvos>= unspecified < 13.113.1
appletvos>= unspecified < 15.715.7
appletvos16.2
applewatchos< 9.29.2
applewatchos
applewatchos>= unspecified < 9.29.2
applewatchos>= unspecified < 16.216.2
debianwebkit2gtk< webkit2gtk 2.38.3-1 (bookworm)webkit2gtk 2.38.3-1 (bookworm)
debianwpewebkit< webkit2gtk 2.38.3-1 (bookworm)webkit2gtk 2.38.3-1 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is in the WebKit component; detection should focus on WebKit-based browsers and rendering engines processing maliciously crafted web content leading to process memory disclosure.
  • On Linux/Debian systems, flag unpatched webkit2gtk packages older than version 2.38.3-1 (or 2.38.3-1~deb11u1 on bullseye) as vulnerable.
  • On Red Hat systems, webkitgtk and webkitgtk3 packages are out of support scope and remain unpatched; treat any deployment of these packages as a persistent risk indicator.
  • ·The vulnerability affects multiple Apple platforms; patched versions are Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS/iPadOS 15.7.2, iOS/iPadOS 16.2, and watchOS 9.2. Devices running older versions remain vulnerable.
  • ·The flaw is rooted in improper input validation leading to memory corruption; exploitation requires the target to process attacker-controlled web content, meaning network access is a prerequisite for remote exploitation.

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
osv6.5MEDIUM
vulncheck6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.