CVE-2022-42823: Race Condition
A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may lead to arbitrary code execution.
Other sources
Accelerate Framework. A memory consumption issue was addressed with improved memory handling.
— Apple
APFS. An access issue was addressed with improved access restrictions.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
Apple TV. The issue was addressed with improved handling of caches.
— Apple
AppleAVD. A memory corruption issue was addressed with improved state management.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.38.6-0+deb10u1Fixed in 2.40.5-1~deb11u1Fixed in 2.42.1-1~deb11u2Fixed in 2.40.5-1~deb12u1Fixed in 2.42.1-1~deb12u1Fixed in 2.42.1-2 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.38.6-1~deb11u1Fixed in 2.38.6-1Fixed in 2.42.1-1 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 16.1 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 9.1 - Upgrade
Upgrade
macOSto a version that resolves this vulnerability.Fixed in 12.6.1 - Upgrade
Upgrade
macOS Venturato a version that resolves this vulnerability.Fixed in 13 - Upgrade
Upgrade
Safarito a version that resolves this vulnerability.Fixed in 16.1 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 16.1 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 16 - Upgrade
Upgrade
redhat/WebKitGTKto a version that resolves this vulnerability.Fixed in 2.38.2 - Upgrade
Upgrade
WebKitGTK and WPE WebKitto a version that resolves this vulnerability.Fixed in 2.38.2 - Upgrade
Upgrade
Rubyto a version that resolves this vulnerability.Fixed in 2.6.10 - Upgrade
Upgrade
curlto a version that resolves this vulnerability.Fixed in 7.84.0 - Upgrade
Upgrade
watchOSto a version that resolves this vulnerability.Fixed in 9.1 - Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 16.1 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 16.1 - Configuration
Enable the added sandbox restrictions on third party apps (additional restrictions are described in the provided material).
Apple sandbox additional sandbox restrictions on third party apps = enable - Configuration
Apply the additional restrictions around the observability of app states (described as being addressed with additional restrictions).
Apple sandbox access restrictions/observability of app states = restrict - Configuration
Ensure the updated code signature validation logic with improved checks is in place (described as being addressed with improved checks).
Apple code signature validation validation checks = improved - Configuration
Remove additional entitlements as part of the fix (described as being addressed by removing additional entitlements).
Apple entitlements entitlements = remove additional entitlements - Configuration
Apply the fix that improves permission validation (described as being addressed with improved permission validation).
Application permissions validation permission validation = improved - Configuration
Apply the fix that improves validation of symlinks (described as being addressed with improved validation of symlinks).
Symlink handling symlink validation = improved - Compensating control
If upgrades are not immediately possible, mitigate exposure by applying the described additional sandbox/access restrictions (e.g., for third-party apps and sensitive/observability behaviors) until fixed versions are deployed.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2022-42825
- CVE-2022-42798
- CVE-2022-32940
- CVE-2022-42813
- CVE-2022-46712
- CVE-2022-32924
- CVE-2022-42808
- CVE-2022-32944
- CVE-2022-42803
- CVE-2022-32926
- CVE-2022-42801
- CVE-2022-42810
- CVE-2022-42811
- CVE-2022-42799
- CVE-2022-42823
- CVE-2022-42824
- CVE-2022-32923
- CVE-2022-32932
- CVE-2022-32947
- CVE-2022-42817
- CVE-2022-37434
- CVE-2022-42800
- CVE-2022-42860
- CVE-2022-46723
- CVE-2022-46713
- CVE-2022-32941
- CVE-2022-28739
- CVE-2022-32862
- CVE-2022-42795
- CVE-2022-48577
- CVE-2022-32858
- CVE-2022-32898
- CVE-2022-32899
- CVE-2022-46721
- CVE-2022-47915
- CVE-2022-47965
- CVE-2022-32889
- CVE-2022-32907
- CVE-2022-32827
- CVE-2022-32877
- CVE-2022-42789
- CVE-2022-46722
- CVE-2022-32902
- CVE-2022-32904
- CVE-2022-32890
- CVE-2022-42796
- CVE-2022-42816
- CVE-2022-42821
- CVE-2022-42819
- CVE-2022-26730
- CVE-2022-32945
- CVE-2022-42838
- CVE-2022-48683
- CVE-2022-22663
- CVE-2022-32867
- CVE-2022-32205
- CVE-2022-32206
- CVE-2022-32207
- CVE-2022-32208
- CVE-2022-42814
- CVE-2022-32865
- CVE-2022-32915
- CVE-2022-32928
- CVE-2022-22643
- CVE-2022-32935
- CVE-2022-42788
- CVE-2022-48504
- CVE-2022-32905
- CVE-2022-42833
- CVE-2022-42809
- CVE-2022-3437
- CVE-2022-32849
- CVE-2022-32913
- CVE-2022-32809
- CVE-2022-1622
- CVE-2022-32936
- CVE-2022-42820
- CVE-2022-42806
- CVE-2022-32864
- CVE-2022-32866
- CVE-2022-32911
- CVE-2022-32914
- CVE-2022-42815
- CVE-2022-42834
- CVE-2022-46707
- CVE-2022-32883
- CVE-2022-32908
- CVE-2021-39537
- CVE-2022-29458
- CVE-2022-42818
- CVE-2022-32879
- CVE-2022-32895
- CVE-2022-42807
- CVE-2022-32918
- CVE-2022-42829
- CVE-2022-42830
- CVE-2022-42831
- CVE-2022-42832
- CVE-2022-32881
- CVE-2022-32931
- CVE-2022-42793
- CVE-2022-32876
- CVE-2022-32938
- CVE-2022-42790
- CVE-2022-32870
- CVE-2022-32934
- CVE-2022-42791
- CVE-2021-36690
- CVE-2022-48505
- CVE-2022-26699
- CVE-2022-0261
- CVE-2022-0318
- CVE-2022-0319
- CVE-2022-0351
- CVE-2022-0359
- CVE-2022-0361
- CVE-2022-0368
- CVE-2022-0392
- CVE-2022-0554
- CVE-2022-0572
- CVE-2022-0629
- CVE-2022-0685
- CVE-2022-0696
- CVE-2022-0714
- CVE-2022-0729
- CVE-2022-0943
- CVE-2022-1381
- CVE-2022-1420
- CVE-2022-1725
- CVE-2022-1616
- CVE-2022-1619
- CVE-2022-1620
- CVE-2022-1621
- CVE-2022-1629
- CVE-2022-1674
- CVE-2022-1733
- CVE-2022-1735
- CVE-2022-1769
- CVE-2022-1927
- CVE-2022-1942
- CVE-2022-1968
- CVE-2022-1851
- CVE-2022-1897
- CVE-2022-1898
- CVE-2022-1720
- CVE-2022-2000
- CVE-2022-2042
- CVE-2022-2124
- CVE-2022-2125
- CVE-2022-2126
- CVE-2022-42828
- CVE-2022-32875
- CVE-2022-42826
- CVE-2022-32886
- CVE-2022-32888
- CVE-2022-32912
- CVE-2022-32922
- CVE-2022-32892
- CVE-2022-32833
- CVE-2022-46709
- CVE-2022-32909
- CVE-2022-32929
- CVE-2022-32946
- CVE-2022-32939
- CVE-2022-42827
- CVE-2022-46715
- CVE-2022-42792
- CVE-2022-32927
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2022-42823.
What software is affected by this vulnerability?
The vulnerability affects Apple macOS Monterey up to version 12.6.1, Apple iOS up to version 16.1, Apple iPadOS up to version 16, Apple watchOS up to version 9.1, Apple Safari up to version 16.1, Apple tvOS up to version 16.1, and Apple macOS Ventura up to version 13.
What is the impact of this vulnerability?
The impact of this vulnerability is a type confusion issue that could lead to arbitrary code execution.
How can I fix this vulnerability?
To fix this vulnerability, update your software to the latest version available, as specified in the Apple security advisory.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability in the Apple security advisory linked in the references section.