Buffer overflow in WebKitGTK+ and WPE WebKit - CVE-2022-46696
Published: December 13, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in WebKit when processing HTML content. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.
Affected software
WPE WebKit
watchOS
macOS
iPadOS
Apple iOS
tvOS
Apple Safari
How to mitigate CVE-2022-46696
macOS - update to 13.1 22C65
Apple Safari - update to 16.2
iPadOS - update to 16.2 20C65
Apple iOS - update to 16.2 20C65
tvOS - update to 16.2 20K362