---
cve: "CVE-2022-42863"
severity: "HIGH"
cvss: 8.8
epss: "1.1%"
vendor: "Apple"
kev: false
exploited: false
published: "2022-12-15 19:15:25"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-08-31T06:21:54+02:00"
---

# CVE-2022-42863

> 8.8 HIGH

## Beschreibung

A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Erforderlich | good |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <https://support.apple.com/en-us/HT213535>
- <https://support.apple.com/en-us/HT213532>
- <https://support.apple.com/en-us/HT213530>
- <https://support.apple.com/en-us/HT213536>
- <https://support.apple.com/en-us/HT213537>
- <http://seclists.org/fulldisclosure/2022/Dec/20>
- <http://seclists.org/fulldisclosure/2022/Dec/23>
- <http://seclists.org/fulldisclosure/2022/Dec/26>
- <http://seclists.org/fulldisclosure/2022/Dec/28>
- <http://seclists.org/fulldisclosure/2022/Dec/27>
- <http://www.openwall.com/lists/oss-security/2022/12/26/1>
- <https://security.gentoo.org/glsa/202305-32>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2022-42863) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
