CERT-In Vulnerability Note
CIVN-2022-0475
Multiple Vulnerabilities in Apple Safari
Original Issue Date:December 16, 2022
Severity Rating: HIGH
Software Affected
- Apple Safari versions prior to 16.2
- Apple iOS version prior to 15.1
Overview
Multiple vulnerabilities have been reported in Apple Safari which could be exploited by an attacker to execute arbitrary code, bypass implemented security restrictions, disclosure of process memory, gain access to potentially sensitive information and bypass Same Origin Policy on the targeted system.
Description
These vulnerabilities are due to boundary error, logic issue, use after free issue excessive, type confusion error in WebKit while processing maliciously crafted web content.
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code, bypass implemented security restrictions, disclosure of process memory, gain access to potentially sensitive information and bypass Same Origin Policy on the targeted system.
Solution
Apply appropriate upgrade as mentioned in advisory:
https://support.apple.com/en-us/HT213537
Vendor Information
Apple
https://support.apple.com/en-us/HT213537
References
Apple
https://support.apple.com/en-us/HT213537
CVE Name
CVE-2022-42852
CVE-2022-42856
CVE-2022-42863
CVE-2022-42867
CVE-2022-46691
CVE-2022-46692
CVE-2022-46696
CVE-2022-46698
CVE-2022-46699
CVE-2022-46700
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|