{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"state":"PUBLISHED","cveId":"CVE-2022-42867","assignerOrgId":"286789f9-fbc2-4510-9f9a-43facdede74c","assignerShortName":"apple","dateUpdated":"2025-04-21T14:43:08.737Z","dateReserved":"2022-10-11T00:00:00.000Z","datePublished":"2022-12-15T00:00:00.000Z"},"containers":{"cna":{"providerMetadata":{"orgId":"286789f9-fbc2-4510-9f9a-43facdede74c","shortName":"apple","dateUpdated":"2023-05-30T05:10:59.329Z"},"descriptions":[{"lang":"en","value":"A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution."}],"affected":[{"vendor":"Apple","product":"tvOS","versions":[{"version":"unspecified","lessThan":"16.2","status":"affected","versionType":"custom"}]},{"vendor":"Apple","product":"tvOS","versions":[{"version":"unspecified","lessThan":"13.1","status":"affected","versionType":"custom"}]},{"vendor":"Apple","product":"tvOS","versions":[{"version":"unspecified","lessThan":"16.2","status":"affected","versionType":"custom"}]},{"vendor":"Apple","product":"watchOS","versions":[{"version":"unspecified","lessThan":"9.2","status":"affected","versionType":"custom"}]},{"vendor":"Apple","product":"watchOS","versions":[{"version":"unspecified","lessThan":"16.2","status":"affected","versionType":"custom"}]}],"references":[{"url":"https://support.apple.com/en-us/HT213535"},{"url":"https://support.apple.com/en-us/HT213532"},{"url":"https://support.apple.com/en-us/HT213530"},{"url":"https://support.apple.com/en-us/HT213536"},{"url":"https://support.apple.com/en-us/HT213537"},{"name":"20221220 APPLE-SA-2022-12-13-1 iOS 16.2 and iPadOS 16.2","tags":["mailing-list"],"url":"http://seclists.org/fulldisclosure/2022/Dec/20"},{"name":"20221220 APPLE-SA-2022-12-13-4 macOS Ventura 13.1","tags":["mailing-list"],"url":"http://seclists.org/fulldisclosure/2022/Dec/23"},{"name":"20221220 APPLE-SA-2022-12-13-7 tvOS 16.2","tags":["mailing-list"],"url":"http://seclists.org/fulldisclosure/2022/Dec/26"},{"name":"20221220 APPLE-SA-2022-12-13-9 Safari 16.2","tags":["mailing-list"],"url":"http://seclists.org/fulldisclosure/2022/Dec/28"},{"name":"20221220 APPLE-SA-2022-12-13-8 watchOS 9.2","tags":["mailing-list"],"url":"http://seclists.org/fulldisclosure/2022/Dec/27"},{"name":"[oss-security] 20221226 WebKitGTK and WPE WebKit Security Advisory WSA-2022-0011","tags":["mailing-list"],"url":"http://www.openwall.com/lists/oss-security/2022/12/26/1"},{"url":"https://security.gentoo.org/glsa/202305-32"}],"problemTypes":[{"descriptions":[{"type":"text","lang":"en","description":"Processing maliciously crafted web content may lead to arbitrary code execution"}]}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-03T13:19:05.296Z"},"title":"CVE Program Container","references":[{"url":"https://support.apple.com/en-us/HT213535","tags":["x_transferred"]},{"url":"https://support.apple.com/en-us/HT213532","tags":["x_transferred"]},{"url":"https://support.apple.com/en-us/HT213530","tags":["x_transferred"]},{"url":"https://support.apple.com/en-us/HT213536","tags":["x_transferred"]},{"url":"https://support.apple.com/en-us/HT213537","tags":["x_transferred"]},{"name":"20221220 APPLE-SA-2022-12-13-1 iOS 16.2 and iPadOS 16.2","tags":["mailing-list","x_transferred"],"url":"http://seclists.org/fulldisclosure/2022/Dec/20"},{"name":"20221220 APPLE-SA-2022-12-13-4 macOS Ventura 13.1","tags":["mailing-list","x_transferred"],"url":"http://seclists.org/fulldisclosure/2022/Dec/23"},{"name":"20221220 APPLE-SA-2022-12-13-7 tvOS 16.2","tags":["mailing-list","x_transferred"],"url":"http://seclists.org/fulldisclosure/2022/Dec/26"},{"name":"20221220 APPLE-SA-2022-12-13-9 Safari 16.2","tags":["mailing-list","x_transferred"],"url":"http://seclists.org/fulldisclosure/2022/Dec/28"},{"name":"20221220 APPLE-SA-2022-12-13-8 watchOS 9.2","tags":["mailing-list","x_transferred"],"url":"http://seclists.org/fulldisclosure/2022/Dec/27"},{"name":"[oss-security] 20221226 WebKitGTK and WPE WebKit Security Advisory WSA-2022-0011","tags":["mailing-list","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2022/12/26/1"},{"url":"https://security.gentoo.org/glsa/202305-32","tags":["x_transferred"]}]},{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-416","lang":"en","description":"CWE-416 Use After Free"}]}],"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":8.8,"attackVector":"NETWORK","baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","integrityImpact":"HIGH","userInteraction":"REQUIRED","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"NONE","confidentialityImpact":"HIGH"}},{"other":{"type":"ssvc","content":{"timestamp":"2025-04-21T14:42:36.907823Z","id":"CVE-2022-42867","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-04-21T14:43:08.737Z"}}]}}