ZeroHour

CVE-2022-22620

KEVmass1

WebKit Use-After-Free (CVE-2022-22620) Enables RCE on iOS, iPadOS, and macOS

CISA: Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability

CVSS 3.1
8.8 high
EPSS
16%p97
Published
()
KEV added
AI analysis

CVE-2022-22620 is a use-after-free (CWE-416) in Apple's WebKit browser engine, the component that renders web content on iPhones, iPads, Macs, and Safari. An attacker triggers it by getting a victim to process maliciously crafted web content, such as visiting an attacker-controlled webpage, requiring no privileges and only user interaction with the content. Successful exploitation may lead to arbitrary code execution in the context of the browser, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8 High). All devices running iOS or iPadOS before 15.3.1, macOS Monterey before 12.2.1, or Safari before 15.3 are affected, which effectively means the broad Apple user base at the time of disclosure. Apple reported the issue may have been actively exploited in the wild; it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-02-11 and carries a 16.2% EPSS probability of exploitation in the next 30 days (97th percentile).

What to do: Update iPhones and iPads to iOS/iPadOS 15.3.1, Macs to macOS Monterey 12.2.1, and Safari to version 15.3 (builds 16612.4.9.1.8 or 15612.4.9.1.8), per Apple's vendor instructions. Inventory for devices still on pre-patch versions, prioritizing user workstations and mobile devices that browse web or HTML email content, since WebKit loads content automatically. Note the vulnerability is listed in CISA's KEV catalog with 'apply updates per vendor instructions' as the required action, so patching is the only reliable mitigation.

Affected
Apple iOS (iPhone OS)prior to iOS 15.3.1
Apple iPadOSprior to iPadOS 15.3.1
Apple macOS (Monterey)prior to macOS Monterey 12.2.1
Apple Safariprior to Safari 15.3 (fixed builds 16612.4.9.1.8 and 15612.4.9.1.8)
Estimated exposure
mass≈1 billion+ Apple devices (WebKit is the system web engine on every iPhone, iPad, and Mac) — WebKit ships with and automatically renders web content on all Apple devices, and Apple's active device install base exceeds one billion, so essentially every Apple device on pre-patch OS or Safari versions at disclosure was exposed; exact…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

CISA Known Exploited Vulnerability
Affected
Apple iOS, iPadOS, and macOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
safari, ipados, iphone os, macos
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news