cbcvebase.
CVE-2022-42867
published 2022-12-15

CVE-2022-42867: A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS…

PriorityP266high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
34.57%
98.2th percentile
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.

Affected

17 ranges
VendorProductVersion rangeFixed in
appleios_16.2_and_ipados
appleipados< 16.216.2
appleiphone_os< 16.216.2
applemacos< 13.113.1
applemacos_ventura
applesafari< 16.216.2
applesafari
appletvos< 16.216.2
appletvos>= unspecified < 16.216.2
appletvos>= unspecified < 13.113.1
appletvos16.2
applewatchos< 9.29.2
applewatchos
applewatchos>= unspecified < 9.29.2
applewatchos>= unspecified < 16.216.2
debianwebkit2gtk< webkit2gtk 2.38.3-1 (bookworm)webkit2gtk 2.38.3-1 (bookworm)
debianwpewebkit< webkit2gtk 2.38.3-1 (bookworm)webkit2gtk 2.38.3-1 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is triggered by processing maliciously crafted web content via WebKit; monitor for unexpected crashes or arbitrary code execution originating from WebKit-based browsers/renderers (Safari, WebKitGTK)
  • The root cause is a use-after-free in WebKit memory management; detection should focus on heap UAF exploitation patterns in WebKit renderer processes
  • On Linux/Debian systems, flag unpatched webkitgtk versions below 2.38.3-1 as vulnerable
  • Red Hat: webkitgtk and webkitgtk3 packages on RHEL 6/7 are out of support scope and remain unpatched; treat any deployment as permanently vulnerable
  • Attack vector is network-based; an attacker with network access can deliver specially crafted web content to trigger the flaw — monitor for anomalous inbound web content delivery to WebKit consumers
  • ·Fixed in Apple platforms: Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2, iPadOS 16.2, watchOS 9.2 — detections targeting unpatched versions should scope to anything below these versions
  • ·Debian fix is webkitgtk >= 2.38.3-1 across all tracked suites (bookworm, bullseye, forky, sid, trixie); earlier versions remain vulnerable

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.