SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-42867

A use after free issue was addressed with improved memory management.

HIGH 8.8EPSS 34.8%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 34.8%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
34.82% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-416
Affected
apple/safari · apple/ipados · apple/iphone os · apple/macos · apple/tvos · apple/watchos
Source
product-security@apple.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.