cbcvebase.
CVE-2022-46700
published 2022-12-15

CVE-2022-46700: A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and…

PriorityP182high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
1.20%
64.8th percentile
A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.

Affected

21 ranges
VendorProductVersion rangeFixed in
appleios_15.7.2_and_ipados
appleios_16.2_and_ipados
appleipados>= 15.0 < 15.7.215.7.2
appleipados>= 16.0 < 16.216.2
appleiphone_os>= 15.0 < 15.7.215.7.2
appleiphone_os>= 16.0 < 16.216.2
applemacos
applemacos_ventura
applesafari< 16.216.2
applesafari
appletvos< 16.216.2
appletvos>= unspecified < 16.216.2
appletvos>= unspecified < 13.113.1
appletvos>= unspecified < 15.715.7
appletvos16.2
applewatchos< 9.29.2
applewatchos
applewatchos>= unspecified < 9.29.2
applewatchos>= unspecified < 16.216.2
debianwebkit2gtk< webkit2gtk 2.38.3-1 (bookworm)webkit2gtk 2.38.3-1 (bookworm)
debianwpewebkit< webkit2gtk 2.38.3-1 (bookworm)webkit2gtk 2.38.3-1 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability resides in the WebKit component; detection should focus on WebKit-based browsers and rendering engines processing maliciously crafted web content
  • Affected component is WebKit across multiple Apple platforms (Safari, tvOS, macOS, iOS/iPadOS, watchOS); monitor for exploitation attempts targeting WebKit's input validation in these environments
  • On Debian-based Linux systems, the vulnerable package is webkitgtk; patch to version 2.38.3-1 or later to remediate
  • On Red Hat/CentOS systems, the vulnerable packages are webkitgtk and webkitgtk3; network-accessible attack vector — monitor for unusual web content delivery to WebKitGTK-consuming applications
  • ·No public exploit code, malicious samples, or specific IOCs (hashes, IPs, domains, URLs) have been disclosed for this CVE in the available sources; detection relies on version-based patching verification and behavioral monitoring of WebKit processes
  • ·Red Hat Enterprise Linux 6 (webkitgtk) and RHEL 7 (webkitgtk3) are listed as 'Out of support scope', meaning no official patch will be provided for those platforms

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vulncheck8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.