CVE-2022-42817: Use After Free
A logic issue was addressed with improved state management. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16, watchOS 9.1. Visiting a maliciously crafted website may leak sensitive data.
Other sources
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
Apple TV. The issue was addressed with improved handling of caches.
— Apple
AppleMobileFileIntegrity. This issue was addressed by removing additional entitlements.
— Apple
Audio. The issue was addressed with improved memory handling.
— Apple
AVEVideoEncoder. The issue was addressed with improved bounds checks.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2022-42825
- CVE-2022-32932
- CVE-2022-42798
- CVE-2022-32940
- CVE-2022-42813
- CVE-2022-32947
- CVE-2022-46712
- CVE-2022-32924
- CVE-2022-42808
- CVE-2022-32944
- CVE-2022-42803
- CVE-2022-32926
- CVE-2022-42801
- CVE-2022-42817
- CVE-2022-42811
- CVE-2022-42799
- CVE-2022-42823
- CVE-2022-42824
- CVE-2022-32923
- CVE-2022-37434
- CVE-2022-42800
- CVE-2022-32909
- CVE-2022-32929
- CVE-2022-32945
- CVE-2022-32946
- CVE-2022-32935
- CVE-2022-32939
- CVE-2022-42820
- CVE-2022-42806
- CVE-2022-42827
- CVE-2022-42810
- CVE-2022-46715
- CVE-2022-42828
- CVE-2022-32941
- CVE-2022-42829
- CVE-2022-42830
- CVE-2022-42831
- CVE-2022-42832
- CVE-2022-32938
- CVE-2022-42792
- CVE-2022-42826
- CVE-2022-32922
- CVE-2022-32927
- CVE-2022-32949
Frequently Asked Questions
What is CVE-2022-42817?
CVE-2022-42817 is a vulnerability in Safari that involves a logic issue and has been addressed with improved state management.
Which software versions are affected by CVE-2022-42817?
CVE-2022-42817 affects Apple iOS versions up to and excluding 16.1, Apple iPadOS versions up to and excluding 16, Apple iOS versions up to and excluding 15.7.1, Apple iPadOS versions up to and excluding 15.7.1, and Apple watchOS versions up to and excluding 9.1.
How can I fix the CVE-2022-42817 vulnerability?
To fix the CVE-2022-42817 vulnerability, update your affected Apple devices to the recommended versions specified by Apple in the provided support links.