CVE-2022-42856
published 2022-12-15CVE-2022-42856: A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS…
PriorityP188high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2023-01-04
Exploited in the wild
EPSS
8.52%
94.4th percentile
A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1..
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | ios | — | — |
| apple | ios_15.7.2_and_ipados | — | — |
| apple | ios_16.2_and_ipados | — | — |
| apple | ipados | < 15.7.2 | 15.7.2 |
| apple | iphone_os | < 15.7.2 | 15.7.2 |
| apple | iphone_os | >= 16.0 < 16.1.2 | 16.1.2 |
| apple | macos | < 13.1 | 13.1 |
| apple | macos_ventura | — | — |
| apple | safari | < 16.2 | 16.2 |
| apple | safari | — | — |
| apple | tvos | < 16.2 | 16.2 |
| apple | tvos | >= unspecified < 16.2 | 16.2 |
| apple | tvos | >= unspecified < 13.1 | 13.1 |
| apple | tvos | >= unspecified < 15.7 | 15.7 |
| apple | tvos | >= unspecified < 16.1 | 16.1 |
| apple | tvos16.2 | — | — |
| debian | webkit2gtk | < webkit2gtk 2.38.3-1 (bookworm) | webkit2gtk 2.38.3-1 (bookworm) |
| debian | wpewebkit | < webkit2gtk 2.38.3-1 (bookworm) | webkit2gtk 2.38.3-1 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2022-42856 is a WebKit type confusion vulnerability actively exploited in the wild against iOS versions released before iOS 15.1; monitor for exploitation attempts via maliciously crafted web content delivered to WebKit-based browsers on Apple devices. ↗
- →CISA flagged this as a Known Exploited Vulnerability with a remediation deadline of 2023-01-04; prioritise detection and patching on unmanaged or legacy Apple iOS devices (pre-iOS 15.1) as the confirmed in-the-wild exploitation target. ↗
- ·Exploitation was confirmed only against iOS versions released before iOS 15.1; devices on iOS 15.1 or later (up to the patched releases) may still be vulnerable but were not the confirmed in-the-wild target. ↗
- ·Fixed versions span multiple product lines; ensure detection/patching scope covers Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS/iPadOS 15.7.2, iOS 16.1.2, and iOS 12.5.7 (legacy devices). ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2022-42856: iOS 12.5.7
vendor_apple·2023-01-23·CVSS 8.8
CVE-2022-42856 [HIGH] CVE-2022-42856: iOS 12.5.7
Apple Security Update: About the security content of iOS 12.5.7
Product: iOS
Version: 12.5.7
CVE: CVE-2022-42856
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1.
Description: A type confusion issue was addressed with improved state handling.
Ubuntu
WebKitGTK vulnerabilities
vendor_ubuntu·2023-01-09
CVE-2022-46699 WebKitGTK vulnerabilities
Title: WebKitGTK vulnerabilities
Summary: Several security issues were fixed in WebKitGTK.
Several security issues were discovered in the WebKitGTK Web and JavaScript
engines. If a user were tricked into viewing a malicious website, a remote
attacker could exploit a variety of issues related to web browser security,
including cross-site scripting attacks, denial of service attacks, and
arbitrary code execution.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use WebKitGTK, such as Epiphany, to make all the necessary changes.
CISA
Apple iOS Type Confusion Vulnerability
cisa·2022-12-14·CVSS 8.8
CVE-2022-42856 [HIGH] CWE-843 Apple iOS Type Confusion Vulnerability
Vulnerability: Apple iOS Type Confusion Vulnerability
Affected: Apple iOS
Apple iOS contains a type confusion vulnerability when processing maliciously crafted web content leading to code execution.
Required Action: Apply updates per vendor instructions.
Notes: https://support.apple.com/en-us/HT213516; https://nvd.nist.gov/vuln/detail/CVE-2022-42856
Remediation Due Date: 2023-01-04
Red Hat
webkitgtk: processing maliciously crafted web content may lead to an arbitrary code execution
vendor_redhat·2022-12-14·CVSS 8.8
CVE-2022-42856 [HIGH] CWE-843 webkitgtk: processing maliciously crafted web content may lead to an arbitrary code execution
webkitgtk: processing maliciously crafted web content may lead to an arbitrary code execution
A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1..
A vulnerability was found in webkitgtk, where a type confusion issue was addressed with improved memory handling. By this security flaw processing maliciously crafted web content may lead to arbitrary code execution.
Statement: Red Hat is not aware of any exploitation of this flaw in Linux platforms at this time.
Mit
Apple
CVE-2022-42856: iOS 16.2 and iPadOS 16.2
vendor_apple·2022-12-13·CVSS 8.8
CVE-2022-42856 [HIGH] CVE-2022-42856: iOS 16.2 and iPadOS 16.2
Apple Security Update: About the security content of iOS 16.2 and iPadOS 16.2
Product: iOS 16.2 and iPadOS
Version: 16.2
CVE: CVE-2022-42856
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1.
Description: A type confusion issue was addressed with improved state handling.
Apple
CVE-2022-42856: tvOS16.2
vendor_apple·2022-12-13·CVSS 8.8
CVE-2022-42856 [HIGH] CVE-2022-42856: tvOS16.2
Apple Security Update: About the security content of tvOS16.2
Product: tvOS16.2
CVE: CVE-2022-42856
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1.
Description: A type confusion issue was addressed with improved state handling.
Apple
CVE-2022-42856: iOS 15.7.2 and iPadOS 15.7.2
vendor_apple·2022-12-13·CVSS 8.8
CVE-2022-42856 [HIGH] CVE-2022-42856: iOS 15.7.2 and iPadOS 15.7.2
Apple Security Update: About the security content of iOS 15.7.2 and iPadOS 15.7.2
Product: iOS 15.7.2 and iPadOS
Version: 15.7.2
CVE: CVE-2022-42856
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1.
Description: A type confusion issue was addressed with improved state handling.
Apple
CVE-2022-42856: Safari 16.2
vendor_apple·2022-12-13·CVSS 8.8
CVE-2022-42856 [HIGH] CVE-2022-42856: Safari 16.2
Apple Security Update: About the security content of Safari 16.2
Product: Safari
Version: 16.2
CVE: CVE-2022-42856
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1.
Description: A type confusion issue was addressed with improved state handling.
Apple
CVE-2022-42856: macOS Ventura 13.1
vendor_apple·2022-12-13·CVSS 8.8
CVE-2022-42856 [HIGH] CVE-2022-42856: macOS Ventura 13.1
Apple Security Update: About the security content of macOS Ventura 13.1
Product: macOS Ventura
Version: 13.1
CVE: CVE-2022-42856
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1.
Description: A type confusion issue was addressed with improved state handling.
Apple
CVE-2022-42856: iOS 16.1.2
vendor_apple·2022-11-30·CVSS 8.8
CVE-2022-42856 [HIGH] CVE-2022-42856: iOS 16.1.2
Apple Security Update: About the security content of iOS 16.1.2
Product: iOS
Version: 16.1.2
CVE: CVE-2022-42856
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1.
Description: A type confusion issue was addressed with improved state handling.
Debian
CVE-2022-42856: webkit2gtk - A type confusion issue was addressed with improved state handling. This issue is...
vendor_debian·2022·CVSS 8.8
CVE-2022-42856 [HIGH] CVE-2022-42856: webkit2gtk - A type confusion issue was addressed with improved state handling. This issue is...
A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1..
Scope: local
bookworm: resolved (fixed in 2.38.3-1)
bullseye: resolved (fixed in 2.38.3-1~deb11u1)
forky: resolved (fixed in 2.38.3-1)
sid: resolved (fixed in 2.38.3-1)
trixie: resolved (fixed in 2.38.3-1)
GHSA
GHSA-qh2r-8xvg-hm24: A type confusion issue was addressed with improved state handling
ghsa_unreviewed·2022-12-15
CVE-2022-42856 [HIGH] CWE-843 GHSA-qh2r-8xvg-hm24: A type confusion issue was addressed with improved state handling
A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1..
OSV
CVE-2022-42856: A type confusion issue was addressed with improved state handling
osv·2022-12-15·CVSS 8.8
CVE-2022-42856 [HIGH] CVE-2022-42856: A type confusion issue was addressed with improved state handling
A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1..
VulnCheck
Apple iOS Type Confusion Vulnerability
vulncheck·2022·CVSS 8.8
CVE-2022-42856 [HIGH] CWE-843 Apple iOS Type Confusion Vulnerability
Apple iOS Type Confusion Vulnerability
Apple iOS contains a type confusion vulnerability when processing maliciously crafted web content leading to code execution.
Affected: Apple iOS
Required Action: Apply updates per vendor instructions.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://support.apple.com/kb/HT213516; https://support.apple.com/kb/HT213530; https://support.apple.com/kb/HT213531; https://support.apple.com/kb/HT213532; https://support.apple.com/kb/HT213535; https://support.apple.com/kb/HT213537; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://raw.githubusercontent.com/blackorbird/APT_REPORT/master/summary/2023/360_APT_Annual_Research_Report_2022.pdf; http
No detection rules found.
No public exploits indexed.
Mandiant
Intellexa’s Prolific Zero-Day Exploits Continue
blogs_mandiant·2025-12-03
Intellexa’s Prolific Zero-Day Exploits Continue
Threat Intelligence
# Sanctioned but Still Spying: Intellexa’s Prolific Zero-Day Exploits Continue
December 3, 2025
##### Google Threat Intelligence Group
##### Google Threat Intelligence
Visibility and context on the threats that matter most.
Contact Us & Get a Demo
### Introduction
Despite extensive scrutiny and public reporting, commercial surveillance vendors continue to operate unimpeded. A prominent name continues to surface in the world of mercenary spyware, Intellexa. Known for its “Predator” spyware, the company was sanctioned by the US Government. New Google Threat Intelligence Group (GTIG) analysis shows that Intellexa is evading restrictions and thriving.
Intellexa has adapted, evaded restrictions, and continues selling digital weapons to the highest bidders. Alongside
Mandiant
Sanctioned but Still Spying: Intellexa’s Prolific Zero-Day Exploits Continue
blogs_mandiant·2025-12-03
Sanctioned but Still Spying: Intellexa’s Prolific Zero-Day Exploits Continue
## Sanctioned but Still Spying: Intellexa’s Prolific Zero-Day Exploits Continue
## Google Threat Intelligence Group
## Google Threat Intelligence
Visibility and context on the threats that matter most.
## Introduction
Despite extensive scrutiny and public reporting , commercial surveillance vendors continue to operate unimpeded. A prominent name continues to surface in the world of mercenary spyware, Intellexa. Known for its “Predator” spyware, the company was sanctioned by the US Government . New Google Threat Intelligence Group (GTIG) analysis shows that Intellexa is evading restrictions and thriving .
Intellexa has adapted, evaded restrictions, and continues selling digital weapons to the highest bidders. Alongside research published by our colleagues from Recorded Future and Amne
Sentinelone
Protecting macOS | 7 Strategies for Enterprise Security in 2024
blogs_sentinelone·2024-01-02
Protecting macOS | 7 Strategies for Enterprise Security in 2024
Welcome to 2024! It may be a new year for us all, but it’s very much business as usual for cybersecurity professionals. Last year saw an increase in the number and variety of new threats targeting the macOS platform, and as the influence of the Mac continues to expand in enterprise environments, there is little doubt that 2024 will continue that trend.
In this post, we reflect on the lessons we can learn from the last 12 months of threat activity against Apple’s desktop operating system, and offer 7 strategies for defenders to help bolster their threat hunting, detection and mitigation efforts .
## 1. Don’t Rely on Persistence for Detection
Perhaps the most important lesson that defenders learned from 2023’s crop of macOS malware was that monitoring for persistence methods became a much
Sentinelone
Protecting macOS | 7 Strategies for Enterprise Security in 2024
blogs_sentinelone·2024-01-02
Protecting macOS | 7 Strategies for Enterprise Security in 2024
Welcome to 2024! It may be a new year for us all, but it’s very much business as usual for cybersecurity professionals. Last year saw an increase in the number and variety of new threats targeting the macOS platform, and as the influence of the Mac continues to expand in enterprise environments, there is little doubt that 2024 will continue that trend.
In this post, we reflect on the lessons we can learn from the last 12 months of threat activity against Apple’s desktop operating system, and offer 7 strategies for defenders to help bolster their threat hunting, detection and mitigation efforts.
## 1. Don’t Rely on Persistence for Detection
Perhaps the most important lesson that defenders learned from 2023’s crop of macOS malware was that monitoring for persistence methods became a much
Sentinelone
7 Ways Threat Actors Deliver macOS Malware in the Enterprise
blogs_sentinelone·2023-01-09
7 Ways Threat Actors Deliver macOS Malware in the Enterprise
Our 2022 review of macOS malware revealed that the threats faced by businesses and users running macOS endpoints included an increase in backdoors and cross-platform attack frameworks. Threats like CrateDepression and PyMafka used typosquatting attacks against package repositories to infect users, while ChromeLoader and others like oRAT leveraged malvertising as an infection vector.
However, the infection vector used by many other macOS threats remains unknown. SysJoker, OSX.Gimmick, CloudMensis, Alchimist and the Lazarus-attributed Operation In(ter)ception are just some of those for which researchers still do not know how victims were initially compromised. In these and other cases, researchers happened across the malware either in post-infection analyses or by discovering the samples on
Sentinelone
7 Ways Threat Actors Deliver macOS Malware in the Enterprise
blogs_sentinelone·2023-01-09
7 Ways Threat Actors Deliver macOS Malware in the Enterprise
Our 2022 review of macOS malware revealed that the threats faced by businesses and users running macOS endpoints included an increase in backdoors and cross-platform attack frameworks. Threats like CrateDepression and PyMafka used typosquatting attacks against package repositories to infect users, while ChromeLoader and others like oRAT leveraged malvertising as an infection vector.
However, the infection vector used by many other macOS threats remains unknown. SysJoker , OSX.Gimmick, CloudMensis, Alchimist and the Lazarus-attributed Operation In(ter)ception are just some of those for which researchers still do not know how victims were initially compromised. In these and other cases, researchers happened across the malware either in post-infection analyses or by discovering the samples o
Checkpoint
19th December – Threat Intelligence Report
blogs_checkpoint·2022-12-20
CVE-2022-44673 19th December – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 19th December – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 20th December, please download our Threat_Intelligence Bulletin
TOP ATTACKS AND BREACHES
Information of more than 80,000 security professionals and law enforcement officers is being offered for sale online, after the FBI’s information sharing portal InfraGard has been breached. The attacker has gained access to InfraGard after applying to join the platform impersonating a financial corporation’s CEO, then usi
http://seclists.org/fulldisclosure/2022/Dec/21http://seclists.org/fulldisclosure/2022/Dec/22http://seclists.org/fulldisclosure/2022/Dec/23http://seclists.org/fulldisclosure/2022/Dec/26http://seclists.org/fulldisclosure/2022/Dec/28http://www.openwall.com/lists/oss-security/2022/12/26/1https://security.gentoo.org/glsa/202305-32https://support.apple.com/en-us/HT213516https://support.apple.com/en-us/HT213531https://support.apple.com/en-us/HT213532https://support.apple.com/en-us/HT213535https://support.apple.com/en-us/HT213537http://seclists.org/fulldisclosure/2022/Dec/21http://seclists.org/fulldisclosure/2022/Dec/22http://seclists.org/fulldisclosure/2022/Dec/23http://seclists.org/fulldisclosure/2022/Dec/26http://seclists.org/fulldisclosure/2022/Dec/28http://www.openwall.com/lists/oss-security/2022/12/26/1https://security.gentoo.org/glsa/202305-32https://support.apple.com/en-us/HT213516https://support.apple.com/en-us/HT213531https://support.apple.com/en-us/HT213532https://support.apple.com/en-us/HT213535https://support.apple.com/en-us/HT213537https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-42856
2022-12-15
Published
2022-12-14
Added to CISA KEV
Exploited in the wild