CVE-2022-42867: Use After Free
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Other sources
Accessibility. A logic issue was addressed with improved restrictions.
— Apple
Accounts. This issue was addressed with improved data protection.
— Apple
AMD. A memory corruption issue was addressed with improved input validation.
— Apple
AMD. An out-of-bounds write issue was addressed with improved input validation.
— Apple
AppleAVD. An out-of-bounds write issue was addressed with improved input validation.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2022-42843
- CVE-2022-46694
- CVE-2022-42865
- CVE-2022-42848
- CVE-2022-46693
- CVE-2022-42851
- CVE-2022-42864
- CVE-2022-46690
- CVE-2022-42837
- CVE-2022-46689
- CVE-2022-46701
- CVE-2022-42842
- CVE-2022-42845
- CVE-2022-48618
- CVE-2022-40303
- CVE-2022-40304
- CVE-2022-42855
- CVE-2022-46695
- CVE-2022-42849
- CVE-2022-42866
- CVE-2022-46705
- CVE-2022-42867
- CVE-2022-46691
- CVE-2022-46692
- CVE-2022-42852
- CVE-2022-46696
- CVE-2022-46700
- CVE-2022-46698
- CVE-2022-46699
- CVE-2022-42863
- CVE-2022-42856
- CVE-2022-46717
- CVE-2022-42859
- CVE-2022-46703
- CVE-2022-42858
- CVE-2022-42847
- CVE-2022-42854
- CVE-2022-42853
- CVE-2022-35252
- CVE-2022-32942
- CVE-2022-46720
- CVE-2022-46710
- CVE-2022-46697
- CVE-2022-42861
- CVE-2022-42839
- CVE-2022-46716
- CVE-2022-46704
- CVE-2022-32943
- CVE-2022-42840
- CVE-2022-42862
- CVE-2022-24836
- CVE-2022-29181
- CVE-2022-46718
- CVE-2022-32919
- CVE-2022-46725
- CVE-2022-42841
- CVE-2022-43454
- CVE-2022-48610
- CVE-2022-46702
- CVE-2022-42850
- CVE-2022-42846
- CVE-2022-42844
Frequently Asked Questions
What is CVE-2022-42867?
CVE-2022-42867 is a vulnerability in WebKit that could lead to a use after free issue due to improper memory management.
What software is affected by CVE-2022-42867?
Apple iOS 16.2, Apple iPadOS 16.2, Apple macOS Ventura 13.1, Apple tvOS 16.2, Apple watchOS 9.2, and Apple Safari 16.2 are affected by CVE-2022-42867.
How can this vulnerability be exploited?
The vulnerability can be exploited by an attacker to perform arbitrary code execution or crash the application.
What is the severity of CVE-2022-42867?
The severity of CVE-2022-42867 is high.
How can I fix CVE-2022-42867?
Apply the necessary updates provided by Apple to the affected software versions.