CVE-2022-22624

HIGH

macOS Monterey <12.3 - Use After Free

Title source: llm
STIX 2.1

Description

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.3, iOS 15.4 and iPadOS 15.4, tvOS 15.4, Safari 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.

References (4)

Core 4
Core References
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT213182
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT213183
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT213186
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT213187

Scores

CVSS v3 8.8
EPSS 0.0112
EPSS Percentile 78.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-416
Status published
Products (4)
apple/ipad_os < 15.4
apple/iphone_os < 15.4
apple/macos 12.0 - 12.3
apple/safari < 15.4
Published Sep 23, 2022
Tracked Since Feb 18, 2026