A certificate validation issue existed in the handling of WKWebView. This issue was addressed with improved validation. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. Processing a maliciously crafted certificate may lead to arbitrary code execution.
References
Link | Resource |
---|---|
https://support.apple.com/en-us/HT213488 | Vendor Advisory |
https://support.apple.com/en-us/HT213489 | Vendor Advisory |
https://support.apple.com/en-us/HT213491 | Vendor Advisory |
https://support.apple.com/en-us/HT213492 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: apple
Published: 2022-11-01T00:00:00
Updated: 2022-11-01T00:00:00
Reserved: 2022-10-11T00:00:00
Link: CVE-2022-42813
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-11-01T20:15:23.587
Modified: 2022-11-03T12:54:14.130
Link: CVE-2022-42813
JSON object: View
Redhat Information
No data.
CWE