Back

HIGH KEV

webkitgtk: processing maliciously crafted web content may lead to an arbitrary code execution

Published Dec 15, 2022 ·Due Jan 4, 2023

Description

A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1..

Affected products

Remediation

Red Hat statement

Red Hat is not aware of any exploitation of this flaw in Linux platforms at this time.

Red Hat mitigation

Setting the environment variable JSC_useFTLJIT=0 will disable the vulnerable code. (This will also somewhat slow down JavaScript execution.)

Weaknesses (1)

References (19)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apple
Published Dec 15, 2022
Updated Oct 21, 2025
Reserved Oct 11, 2022
CISA Vulnrichment
Updated Jan 28, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Dec 14, 2022
ENISA EUVD
Assigner apple
Published Dec 15, 2022
Updated Oct 21, 2025
Exploited since Dec 14, 2022
EUVD-2022-45919