CVE-2022-48503
published 2023-08-14CVE-2022-48503: The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6…
PriorityP186high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-11-10
Exploited in the wild
EPSS
3.21%
86.8th percentile
The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing web content may lead to arbitrary code execution.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_15.6_and_ipados | — | — |
| apple | ios_and_ipados | >= unspecified < 15.6 | 15.6 |
| apple | ipados | < 15.6 | 15.6 |
| apple | iphone_os | < 15.6 | 15.6 |
| apple | macos | >= 12.0.0 < 12.5 | 12.5 |
| apple | macos | >= unspecified < 12.5 | 12.5 |
| apple | macos_monterey | — | — |
| apple | safari | < 15.6 | 15.6 |
| apple | safari | — | — |
| apple | safari | >= unspecified < 15.6 | 15.6 |
| apple | tvos | < 15.6 | 15.6 |
| apple | tvos | — | — |
| apple | tvos | >= unspecified < 15.6 | 15.6 |
| apple | watchos | < 8.7 | 8.7 |
| apple | watchos | — | — |
| apple | watchos | >= unspecified < 8.7 | 8.7 |
| debian | webkit2gtk | < webkit2gtk 2.38.0-1 (bookworm) | webkit2gtk 2.38.0-1 (bookworm) |
| debian | wpewebkit | < webkit2gtk 2.38.0-1 (bookworm) | webkit2gtk 2.38.0-1 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
0xf00dbeef
- →CVE-2022-48503 is internally codenamed 'jacurutu' in the Coruna exploit kit and targets iOS 15.2 through 15.5 as a WebContent R/W primitive; detection should focus on WebKit exploitation attempts in that version range. ↗
- →The Coruna exploit kit delivers exploits via a hidden iFrame injected into compromised websites; network monitoring for hidden iFrame injection patterns on legitimate sites can surface delivery infrastructure. ↗
- →The JavaScript obfuscation pattern using XOR-based character encoding (array.map with String.fromCharCode and XOR) is a unique fingerprint of the Coruna framework and can be used for JS-level detection. ↗
- →Binary payloads encrypted with ChaCha20 and served with a .min.js URL extension, combined with the 0xf00dbeef magic header, can be used as a network/file-based detection signature for Coruna payload blobs. ↗
- →The exploit kit bails out if Lockdown Mode or private browsing is detected; absence of exploitation attempts against Lockdown Mode devices can be used as a behavioral indicator to confirm Coruna activity. ↗
- →The affected component is JavaScriptCore; security tooling should monitor for out-of-bounds memory access originating from JavaScriptCore when processing web content on unpatched iOS 15.2–15.5 devices. ↗
- ·The CVE-to-codename mapping in the exploit table is explicitly noted as preliminary; the 'jacurutu' codename association with CVE-2022-48503 may be revised as analysis continues. ↗
- ·All identified domains have been added to Google Safe Browsing, limiting their ongoing utility as network-based IOCs for detection in environments relying on that feed. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hqf2-wqhm-8v23: The issue was addressed with improved bounds checks
ghsa_unreviewed·2023-08-15
CVE-2022-48503 [HIGH] CWE-129 GHSA-hqf2-wqhm-8v23: The issue was addressed with improved bounds checks
The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing web content may lead to arbitrary code execution.
OSV
CVE-2022-48503: The issue was addressed with improved bounds checks
osv·2023-08-14·CVSS 8.8
CVE-2022-48503 [HIGH] CVE-2022-48503: The issue was addressed with improved bounds checks
The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing web content may lead to arbitrary code execution.
VulnCheck
Apple Multiple Products Unspecified Vulnerability
vulncheck·2022·CVSS 8.8
CVE-2022-48503 [HIGH] Apple Multiple Products Unspecified Vulnerability
Apple Multiple Products Unspecified Vulnerability
Apple macOS, iOS, tvOS, Safari, and watchOS contain an unspecified vulnerability in JavaScriptCore that when processing web content may lead to arbitrary code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Affected: Apple Multiple Products
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.loginsoft.com/reports/annually/vulnerability-intelligence-report-2025; https://cloud.google.com/blog/topics/threat
CISA
Apple Multiple Products Unspecified Vulnerability
cisa·2025-10-20·CVSS 8.8
CVE-2022-48503 [HIGH] Apple Multiple Products Unspecified Vulnerability
Vulnerability: Apple Multiple Products Unspecified Vulnerability
Affected: Apple Multiple Products
Apple macOS, iOS, tvOS, Safari, and watchOS contain an unspecified vulnerability in JavaScriptCore that when processing web content may lead to arbitrary code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://support.apple.com/en-us/HT213340 ; https://support.apple.com/en-us/HT213341 ; https://support.apple.com/en-us/HT213342 ; https://support.apple.com/en-us/HT213345 ; https://support.apple.com/en-us/HT213346 ;
Red Hat
webkitgtk: improper bounds checking leading to arbitrary code execution
vendor_redhat·2023-06-29·CVSS 8.8
CVE-2022-48503 [HIGH] CWE-94 webkitgtk: improper bounds checking leading to arbitrary code execution
webkitgtk: improper bounds checking leading to arbitrary code execution
The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing web content may lead to arbitrary code execution.
A vulnerability was found in webkitgtk. This issue occurs when processing web content, which may lead to arbitrary code execution.
Statement: WebKitGTK3 is not required by any package. Therefore, it can be removed without consequences or break of functionality..
WebKitGTK4 is used in Red Hat Enterprise Linux 7 by the following packages: evolution-data-server, glade, gnome-boxes, gnome-initial-setup, gnome-online-accounts, gnome-shell, shotwell, sushi and yelp.
Mitigation: To mitigate this vulnerabi
Apple
CVE-2022-48503: Safari 15.6
vendor_apple·2022-07-20·CVSS 8.8
CVE-2022-48503 [HIGH] CVE-2022-48503: Safari 15.6
Apple Security Update: About the security content of Safari 15.6
Product: Safari
Version: 15.6
CVE: CVE-2022-48503
Component: JavaScriptCore
Impact: Processing web content may lead to arbitrary code execution
Description: The issue was addressed with improved bounds checks.
Apple
CVE-2022-48503: tvOS 15.6
vendor_apple·2022-07-20·CVSS 8.8
CVE-2022-48503 [HIGH] CVE-2022-48503: tvOS 15.6
Apple Security Update: About the security content of tvOS 15.6
Product: tvOS
Version: 15.6
CVE: CVE-2022-48503
Component: JavaScriptCore
Impact: Processing web content may lead to arbitrary code execution
Description: The issue was addressed with improved bounds checks.
Apple
CVE-2022-48503: iOS 15.6 and iPadOS 15.6
vendor_apple·2022-07-20·CVSS 8.8
CVE-2022-48503 [HIGH] CVE-2022-48503: iOS 15.6 and iPadOS 15.6
Apple Security Update: About the security content of iOS 15.6 and iPadOS 15.6
Product: iOS 15.6 and iPadOS
Version: 15.6
CVE: CVE-2022-48503
Component: JavaScriptCore
Impact: Processing web content may lead to arbitrary code execution
Description: The issue was addressed with improved bounds checks.
Apple
CVE-2022-48503: watchOS 8.7
vendor_apple·2022-07-20·CVSS 8.8
CVE-2022-48503 [HIGH] CVE-2022-48503: watchOS 8.7
Apple Security Update: About the security content of watchOS 8.7
Product: watchOS
Version: 8.7
CVE: CVE-2022-48503
Component: JavaScriptCore
Impact: Processing web content may lead to arbitrary code execution
Description: The issue was addressed with improved bounds checks.
Apple
CVE-2022-48503: macOS Monterey 12.5
vendor_apple·2022-07-20·CVSS 8.8
CVE-2022-48503 [HIGH] CVE-2022-48503: macOS Monterey 12.5
Apple Security Update: About the security content of macOS Monterey 12.5
Product: macOS Monterey
Version: 12.5
CVE: CVE-2022-48503
Component: JavaScriptCore
Impact: Processing web content may lead to arbitrary code execution
Description: The issue was addressed with improved bounds checks.
Debian
CVE-2022-48503: webkit2gtk - The issue was addressed with improved bounds checks. This issue is fixed in tvOS...
vendor_debian·2022·CVSS 8.8
CVE-2022-48503 [HIGH] CVE-2022-48503: webkit2gtk - The issue was addressed with improved bounds checks. This issue is fixed in tvOS...
The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.38.0-1)
bullseye: resolved (fixed in 2.38.0-1~deb11u1)
forky: resolved (fixed in 2.38.0-1)
sid: resolved (fixed in 2.38.0-1)
trixie: resolved (fixed in 2.38.0-1)
No detection rules found.
No public exploits indexed.
Mandiant
Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit
blogs_mandiant·2026-03-03
Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit
Threat Intelligence
# Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit
March 3, 2026
##### Google Threat Intelligence Group
##### Google Threat Intelligence
Visibility and context on the threats that matter most.
Contact Us & Get a Demo
### Introduction
Google Threat Intelligence Group (GTIG) has identified a new and powerful exploit kit targeting Apple iPhone models running iOS version 13.0 (released in September 2019) up to version 17.2.1 (released in December 2023). The exploit kit, named “Coruna” by its developers, contained five full iOS exploit chains and a total of 23 exploits. The core technical value of this exploit kit lies in its comprehensive collection of iOS exploits, with the most advanced ones using non-public exploitation techniques and mitigation bypas
Mandiant
Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit
blogs_mandiant·2026-03-03
Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit
## Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit
## Google Threat Intelligence Group
## Google Threat Intelligence
Visibility and context on the threats that matter most.
## Introduction
Google Threat Intelligence Group (GTIG) has identified a new and powerful exploit kit targeting Apple iPhone models running iOS version 13.0 (released in September 2019) up to version 17.2.1 (released in December 2023) . The exploit kit, named “Coruna” by its developers, contained five full iOS exploit chains and a total of 23 exploits. The core technical value of this exploit kit lies in its comprehensive collection of iOS exploits, with the most advanced ones using non-public exploitation techniques and mitigation bypasses.
The Coruna exploit kit provides another example of how sophi
Recorded Future
October 2025 CVE Landscape
blogs_recorded_future·CVSS 9.8
[CRITICAL] October 2025 CVE Landscape
# October 2025 CVE Landscape: 32 High-Impact Vulnerabilities Demand Immediate Attention
October 2025 saw a significant escalation in vulnerability activity, with Recorded Future's Insikt Group® identifying 32 high-impact vulnerabilities, double the 16 identified in September's CVE report. Twenty-six of these vulnerabilities scored as Very Critical.
What security teams need to know:
- Microsoft dominates: Eight of 32 vulnerabilities affect Microsoft products, including a critical WSUS deserialization flaw (CVE-2025-59287) now being actively exploited
- CL0P ransomware group exploited an Oracle E-Business Suite zero-day (CVE-2025-61882) for data theft and extortion campaigns
- Legacy vulnerabilities persist: Five of the 14 RCE-enabling vulnerabilities are over a decade old, highlighting c
https://support.apple.com/en-us/HT213340https://support.apple.com/en-us/HT213341https://support.apple.com/en-us/HT213342https://support.apple.com/en-us/HT213345https://support.apple.com/en-us/HT213346https://support.apple.com/en-us/HT213340https://support.apple.com/en-us/HT213341https://support.apple.com/en-us/HT213342https://support.apple.com/en-us/HT213345https://support.apple.com/en-us/HT213346https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-48503
2023-08-14
Published
2025-10-20
Added to CISA KEV
Exploited in the wild