CVE-2022-48503
9.5 CISA KEVApple · macOS, tvOS, Safari, watchOS, iOS, iPadOS
A memory corruption vulnerability in Apple's web content processing engine allows unauthenticated attackers to achieve arbitrary code execution by processing malicious web content.
Executive summary
This critical memory corruption vulnerability in Apple products is confirmed to be actively exploited in the wild and requires immediate patching to prevent arbitrary code execution.
Vulnerability
The flaw resides within the web content processing engine, specifically involving insufficient bounds checks in the JavaScriptCore component of WebKit. An unauthenticated remote attacker can trigger this vulnerability by enticing a user to process malicious web content, leading to arbitrary code execution on the target device.
Business impact
With a CVSS score of 9.5, this vulnerability represents a critical risk to organizational security. Successful exploitation grants an attacker the ability to execute arbitrary code with the privileges of the logged in user, potentially leading to full system compromise, data theft, and the installation of persistent malware. Given its inclusion in the CISA Known Exploited Vulnerability catalog, the risk of targeted attacks against unpatched systems is extremely high.
Remediation
Immediate Action: Update all affected Apple devices to the following versions: macOS Monterey 12.5, tvOS 15.6, watchOS 8.7, iOS 15.6, iPadOS 15.6, or Safari 15.6.
Proactive Monitoring: Review system logs for signs of unauthorized process execution or unexpected browser behavior, particularly on devices that handle external web traffic.
Compensating Controls: Use network filtering and web proxy solutions to block access to known malicious domains, and enforce strict endpoint security policies to limit the impact of potential code execution.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this vulnerability, combined with its confirmed status as an actively exploited entry in the CISA KEV catalog, necessitates an emergency patching cycle. IT administrators must prioritize the immediate deployment of the specified updates across all managed Apple hardware to mitigate the threat of remote compromise. Failure to patch these devices leaves the organization vulnerable to ongoing exploitation efforts.