CVE-2022-42856 is a type confusion vulnerability affecting Apple's Safari, tvOS, macOS, iOS, and iPadOS. This flaw, rated 8.8 HIGH, allows arbitrary code execution when processing maliciously crafted web content, requiring user interaction to trigger. Apple has confirmed active exploitation of this zero-day vulnerability, particularly against iOS versions prior to 15.1, though no public exploit code is currently available. The issue has garnered significant community attention and media coverage, indicating its critical nature.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 16.2CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
< 15.7.2CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 15.7.2CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
>= 16.0, < 16.1.2CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 13.1CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.