CVE-2022-42799: Race Condition
Accelerate Framework. A memory consumption issue was addressed with improved memory handling.
Other sources
APFS. An access issue was addressed with improved access restrictions.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
Apple TV. The issue was addressed with improved handling of caches.
— Apple
AppleAVD. A memory corruption issue was addressed with improved state management.
— Apple
AppleAVD. This issue was addressed with improved checks.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.38.6-0+deb10u1Fixed in 2.40.5-1~deb11u1Fixed in 2.42.1-1~deb11u2Fixed in 2.40.5-1~deb12u1Fixed in 2.42.1-1~deb12u1Fixed in 2.42.1-2 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.38.6-1~deb11u1Fixed in 2.38.6-1Fixed in 2.42.1-1 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 16.1 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 9.1 - Upgrade
Upgrade
macOS Venturato a version that resolves this vulnerability.Fixed in 13 - Upgrade
Upgrade
Safarito a version that resolves this vulnerability.Fixed in 16.1 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 16.1 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 16 - Upgrade
Upgrade
redhat/WebKitGTKto a version that resolves this vulnerability.Fixed in 2.38.2 - Upgrade
Upgrade
WebKitGTK and WPE WebKitto a version that resolves this vulnerability.Fixed in 2.38.2 - Upgrade
Upgrade
curlto a version that resolves this vulnerability.Fixed in 7.84.0 - Upgrade
Upgrade
Rubyto a version that resolves this vulnerability.Fixed in 2.6.10 - Upgrade
Upgrade
watchOSto a version that resolves this vulnerability.Fixed in 9.1 - Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 16.1 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 16.1 - Configuration
Reduce observability of app states by applying additional restrictions (observability limitation addressed with additional restrictions on the observability of app states).
Sandbox app observability of app states = restricted (additional restrictions) - Configuration
Strengthen code signature validation checks to prevent unauthorized actions (issue addressed with improved checks for code signature validation / preventing unauthorized actions).
Code signing validation validation checks = improved (stronger validation) - Compensating control
For third-party apps, add/strengthen sandbox restrictions (access issue addressed with additional sandbox restrictions on third party apps / third-party apps / additional restrictions).
- Operational
For WebKit/WPE WebKit users, apply the WebKitGTK/WPE WebKit update to 2.38.2 before continued browsing of potentially malicious sites (UI spoofing risk from visiting a malicious website).
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2022-42825
- CVE-2022-42798
- CVE-2022-32940
- CVE-2022-42813
- CVE-2022-46712
- CVE-2022-32924
- CVE-2022-42808
- CVE-2022-32944
- CVE-2022-42803
- CVE-2022-32926
- CVE-2022-42801
- CVE-2022-42810
- CVE-2022-42811
- CVE-2022-42799
- CVE-2022-42823
- CVE-2022-42824
- CVE-2022-32923
- CVE-2022-32932
- CVE-2022-32947
- CVE-2022-42817
- CVE-2022-37434
- CVE-2022-42800
- CVE-2022-42795
- CVE-2022-48577
- CVE-2022-32858
- CVE-2022-32898
- CVE-2022-32899
- CVE-2022-46721
- CVE-2022-47915
- CVE-2022-47965
- CVE-2022-32889
- CVE-2022-32907
- CVE-2022-32827
- CVE-2022-32877
- CVE-2022-42789
- CVE-2022-46722
- CVE-2022-32902
- CVE-2022-32904
- CVE-2022-32890
- CVE-2022-42796
- CVE-2022-42816
- CVE-2022-42821
- CVE-2022-42860
- CVE-2022-42819
- CVE-2022-26730
- CVE-2022-32945
- CVE-2022-42838
- CVE-2022-48683
- CVE-2022-22663
- CVE-2022-32867
- CVE-2022-32205
- CVE-2022-32206
- CVE-2022-32207
- CVE-2022-32208
- CVE-2022-42814
- CVE-2022-32865
- CVE-2022-32915
- CVE-2022-32928
- CVE-2022-22643
- CVE-2022-32935
- CVE-2022-42788
- CVE-2022-48504
- CVE-2022-32905
- CVE-2022-42833
- CVE-2022-42809
- CVE-2022-3437
- CVE-2022-32849
- CVE-2022-32913
- CVE-2022-32809
- CVE-2022-1622
- CVE-2022-32936
- CVE-2022-42820
- CVE-2022-42806
- CVE-2022-32864
- CVE-2022-32866
- CVE-2022-32911
- CVE-2022-32914
- CVE-2022-42815
- CVE-2022-42834
- CVE-2022-46707
- CVE-2022-32883
- CVE-2022-32908
- CVE-2021-39537
- CVE-2022-29458
- CVE-2022-42818
- CVE-2022-32879
- CVE-2022-32895
- CVE-2022-46713
- CVE-2022-42807
- CVE-2022-32918
- CVE-2022-42829
- CVE-2022-42830
- CVE-2022-42831
- CVE-2022-42832
- CVE-2022-32941
- CVE-2022-28739
- CVE-2022-32881
- CVE-2022-32862
- CVE-2022-32931
- CVE-2022-42793
- CVE-2022-32876
- CVE-2022-32938
- CVE-2022-42790
- CVE-2022-32870
- CVE-2022-32934
- CVE-2022-42791
- CVE-2021-36690
- CVE-2022-48505
- CVE-2022-26699
- CVE-2022-0261
- CVE-2022-0318
- CVE-2022-0319
- CVE-2022-0351
- CVE-2022-0359
- CVE-2022-0361
- CVE-2022-0368
- CVE-2022-0392
- CVE-2022-0554
- CVE-2022-0572
- CVE-2022-0629
- CVE-2022-0685
- CVE-2022-0696
- CVE-2022-0714
- CVE-2022-0729
- CVE-2022-0943
- CVE-2022-1381
- CVE-2022-1420
- CVE-2022-1725
- CVE-2022-1616
- CVE-2022-1619
- CVE-2022-1620
- CVE-2022-1621
- CVE-2022-1629
- CVE-2022-1674
- CVE-2022-1733
- CVE-2022-1735
- CVE-2022-1769
- CVE-2022-1927
- CVE-2022-1942
- CVE-2022-1968
- CVE-2022-1851
- CVE-2022-1897
- CVE-2022-1898
- CVE-2022-1720
- CVE-2022-2000
- CVE-2022-2042
- CVE-2022-2124
- CVE-2022-2125
- CVE-2022-2126
- CVE-2022-42828
- CVE-2022-32875
- CVE-2022-42826
- CVE-2022-32886
- CVE-2022-32888
- CVE-2022-32912
- CVE-2022-32922
- CVE-2022-32892
- CVE-2022-32833
- CVE-2022-46709
- CVE-2022-32909
- CVE-2022-32929
- CVE-2022-32946
- CVE-2022-32939
- CVE-2022-42827
- CVE-2022-46715
- CVE-2022-42792
- CVE-2022-32927
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-42799.
What software is affected by this vulnerability?
The affected software includes Apple iOS up to version 16.1, Apple iPadOS up to version 16, Apple watchOS up to version 9.1, Apple Safari up to version 16.1, Apple tvOS up to version 16.1, and macOS Ventura up to version 13.
How was the vulnerability addressed?
The vulnerability was addressed with improved UI handling.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the Apple support website at the following links: [link1](https://support.apple.com/en-us/HT213489), [link2](https://support.apple.com/en-us/HT213491), [link3](https://support.apple.com/en-us/HT213495).
How do I fix this vulnerability?
To fix this vulnerability, update your software to the latest version provided by Apple.