EXPOSURES › CVE-2022-22620
CVE-2022-22620
HIGH ⌖ ON CISA KEV · EXPLOITEDApple's WebKit in iOS, iPadOS, and macOS suffered a use-after-free vulnerability allowing remote code execution via malicious web content.
A use-after-free flaw in WebKit enabled attackers to execute arbitrary code by processing crafted web pages, directly impacting Apple devices and any software relying on WebKit. This is a critical failure for DIB organizations because it represents an unpatched, actively exploited vulnerability that could compromise endpoint security and violate CMMC/NIST 800-171 controls around software integrity and patch management. Organizations must ensure all WebKit-dependent systems are patched immediately and monitor for similar flaws in third-party components.
Shame score — A use-after-free vulnerability in a core browser engine was actively exploited in the wild, indicating a failure to patch a known, high-severity flaw before it was weaponized.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.