Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3522-8qwx-4h39

Опубликовано: 02 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

A certificate validation issue existed in the handling of WKWebView. This issue was addressed with improved validation. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. Processing a maliciously crafted certificate may lead to arbitrary code execution.

A certificate validation issue existed in the handling of WKWebView. This issue was addressed with improved validation. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. Processing a maliciously crafted certificate may lead to arbitrary code execution.

EPSS

Процентиль: 72%
0.00709
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

A certificate validation issue existed in the handling of WKWebView. This issue was addressed with improved validation. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. Processing a maliciously crafted certificate may lead to arbitrary code execution.

EPSS

Процентиль: 72%
0.00709
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-295