Rewterz
Rewterz Threat Advisory – CVE-2022-0016 – Palo Alto Networks GlobalProtect App Vulnerability
February 11, 2022
Rewterz
Rewterz Threat Advisory – ICS: Schneider Electric Vulnerabilities
February 11, 2022

Rewterz Threat Advisory – CVE-2022-22620 – Apple iOS and iPadOS Vulnerability

Severity

High

Analysis Summary

CVE-2022-22620

Apple iOS and iPadOS and macOS Monterey could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free in the WebKit component. By persuading a victim to open a specially crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system or cause a denial of service.

“Apple is aware of a report that this issue may have been actively exploited,” the company said in their Security Updates

Impact

  • Code Execution

Indicators of Compromise

CVE

  • CVE-2022-22620

Affected Vendors

  • Apple
  • Apple iOS
  • Apple iPadOS

Affected Products

  • iPhone 6s and later
  • iPad Pro (all models)
  • iPad Air 2 and later
  • iPad 5th generation and later
  • iPad mini 4 and later
  • and iPod touch (7th generation)

Remediation

For patches and upgrades, please visit vendor website:

https://support.apple.com/en-us/HT213093