A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1..
Advisories
Source ID Title
Debian DLA Debian DLA DLA-3274-1 webkit2gtk security update
Debian DSA Debian DSA DSA-5308-1 webkit2gtk security update
Debian DSA Debian DSA DSA-5309-1 wpewebkit security update
EUVD EUVD EUVD-2022-45919 A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1..
Ubuntu USN Ubuntu USN USN-5797-1 WebKitGTK vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 22 Oct 2025 08:15:00 +0900


Wed, 22 Oct 2025 05:30:00 +0900


Wed, 22 Oct 2025 04:30:00 +0900


Mon, 07 Jul 2025 23:00:00 +0900

Type Values Removed Values Added
First Time appeared Redhat rhel Els
CPEs cpe:/o:redhat:rhel_els:7
Vendors & Products Redhat rhel Els

Wed, 29 Jan 2025 07:15:00 +0900

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2022-12-14'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 14 Aug 2024 10:00:00 +0900

Type Values Removed Values Added
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2025-10-21T23:15:29.832Z

Reserved: 2022-10-11T00:00:00.000Z

Link: CVE-2022-42856

cve-icon Vulnrichment

Updated: 2024-08-03T13:19:05.404Z

cve-icon NVD

Status : Analyzed

Published: 2022-12-15T19:15:25.123

Modified: 2025-10-23T18:02:34.043

Link: CVE-2022-42856

cve-icon Redhat

Severity : Important

Publid Date: 2022-12-14T00:00:00Z

Links: CVE-2022-42856 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses