CISA Known Exploited Vulnerability
This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.
Remediation Deadline: Feb 25, 2022
Description
Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
EPSS — Exploit Probability
4.0%
Higher than 88.3% of all CVEs
Required Action
https://nvd.nist.gov/vuln/detail/CVE-2022-22620
Risk Assessment
ELEVATEDIn CISA KEV
Details
- Severity
- High
- EPSS
- 4.0%
- CISA KEV
- Yes
- Ransomware
- Unknown
- Articles
- 0
Timeline
Published
Feb 11, 2022
Added to KEV
Feb 11, 2022
Remediation Due
Feb 25, 2022