cbcvebase.
CVE-2022-46691
published 2022-12-15

CVE-2022-46691: A memory consumption issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and…

PriorityP182high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
1.51%
71.6th percentile
A memory consumption issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.

Affected

21 ranges
VendorProductVersion rangeFixed in
appleios_15.7.2_and_ipados
appleios_16.2_and_ipados
appleipados< 15.7.215.7.2
appleipados>= 16.0 < 16.216.2
appleiphone_os< 15.7.215.7.2
appleiphone_os>= 16.0 < 16.216.2
applemacos< 13.113.1
applemacos_ventura
applesafari< 16.216.2
applesafari
appletvos< 16.216.2
appletvos>= unspecified < 16.216.2
appletvos>= unspecified < 13.113.1
appletvos>= unspecified < 15.715.7
appletvos16.2
applewatchos< 9.29.2
applewatchos
applewatchos>= unspecified < 9.29.2
applewatchos>= unspecified < 16.216.2
debianwebkit2gtk< webkit2gtk 2.38.1-1 (bookworm)webkit2gtk 2.38.1-1 (bookworm)
debianwpewebkit< webkit2gtk 2.38.1-1 (bookworm)webkit2gtk 2.38.1-1 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is triggered via processing maliciously crafted web content in WebKit; monitor for suspicious web content rendering activity in WebKit-based browsers/apps
  • Affected component is WebKit across Apple platforms (iOS, iPadOS, tvOS, macOS, Safari, watchOS); prioritize detection/patching on unpatched WebKit versions below the fixed releases
  • On Debian-based Linux systems (using WebKitGTK), flag installations running versions prior to 2.38.1-1 (bookworm/sid/trixie/forky) or 2.38.2-1~deb11u1 (bullseye) as vulnerable
  • ·This is a memory consumption (OOM/resource exhaustion) class vulnerability in WebKit, not a traditional memory corruption bug; exploitation relies on triggering excessive memory usage via crafted web content leading to arbitrary code execution

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vulncheck8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.