A certificate validation issue existed in the handling of WKWebView. This issue was addressed with improved validation. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. Processing a maliciously crafted certificate may lead to arbitrary code execution.
References
Link | Resource |
---|---|
https://support.apple.com/en-us/HT213488 | Vendor Advisory |
https://support.apple.com/en-us/HT213489 | Vendor Advisory |
https://support.apple.com/en-us/HT213491 | Vendor Advisory |
https://support.apple.com/en-us/HT213492 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
03 Nov 2022, 12:54
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* |
|
References | (MISC) https://support.apple.com/en-us/HT213492 - Vendor Advisory | |
References | (MISC) https://support.apple.com/en-us/HT213488 - Vendor Advisory | |
References | (MISC) https://support.apple.com/en-us/HT213491 - Vendor Advisory | |
References | (MISC) https://support.apple.com/en-us/HT213489 - Vendor Advisory | |
CWE | CWE-295 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
First Time |
Apple macos
Apple iphone Os Apple Apple tvos Apple watchos Apple ipados |
01 Nov 2022, 20:17
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-11-01 20:15
Updated : 2023-12-10 14:35
NVD link : CVE-2022-42813
Mitre link : CVE-2022-42813
CVE.ORG link : CVE-2022-42813
JSON object : View
Products Affected
apple
- macos
- tvos
- watchos
- iphone_os
- ipados
CWE
CWE-295
Improper Certificate Validation