CVE-2022-22620
HIGH KEVSafari < 15.3 - Use-After-Free via Malicious Web Content
Title source: llmExploitation Summary
CVE-2022-22620 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added February 11, 2022. EIP tracks 3 public exploits from researchers including springsec, kmeps4, bb33bb.
AI-analyzed exploit summary This repository contains a README describing CVE-2022-22620, a use-after-free vulnerability in Safari (WebKit) leading to an infoleak exploit. It references the original PoC by Google Project Zero and provides testing details for webkitgtk-2.34.3.
Description
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
Exploits (3)
This repository contains a README describing CVE-2022-22620, a use-after-free vulnerability in Safari (WebKit) leading to an infoleak exploit. It references the original PoC by Google Project Zero and provides testing details for webkitgtk-2.34.3.
This repository contains a README file referencing CVE-2022-22620, a use-after-free vulnerability in Safari. It links to Google Project Zero's analysis but does not include exploit code or technical details.
The repository contains only a README.md file with a title and a CVE reference, lacking any actual exploit code or technical details. No proof-of-concept or exploit logic is present.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H