PT-2022-3417 · Apple+8 · Apple Macos+13
Ryuzaki
·
Published
2022-05-16
·
Updated
2023-08-08
·
CVE-2022-26700
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apple iOS versions prior to 15.5
Apple iPadOS versions prior to 15.5
Apple macOS versions prior to 12.4
Apple Safari versions prior to 15.5
Apple tvOS versions prior to 15.5
Apple watchOS versions prior to 8.6
Description
A memory corruption issue was addressed with improved state management. Processing maliciously crafted web content may lead to code execution. The issue is related to insufficient input validation in WebKitGTK and WPE WebKit modules, which can allow a remote attacker to execute arbitrary code or cause a denial of service.
Recommendations
For Apple iOS versions prior to 15.5, update to iOS 15.5 or later.
For Apple iPadOS versions prior to 15.5, update to iPadOS 15.5 or later.
For Apple macOS versions prior to 12.4, update to macOS Monterey 12.4 or later.
For Apple Safari versions prior to 15.5, update to Safari 15.5 or later.
For Apple tvOS versions prior to 15.5, update to tvOS 15.5 or later.
For Apple watchOS versions prior to 8.6, update to watchOS 8.6 or later.
Fix
Memory Corruption
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Almalinux
Astra Linux
Centos
Linuxmint
Apple Macos
Red Hat
Rocky Linux
Safari
Suse
Ubuntu
Ios
Ipados
Tvos
Watchos