← Apple

August 2022 — WebKit and kernel zero-days (CVE-2022-32893, CVE-2022-32894)

2022 Unknown records affected Share on X

Data compromised

Arbitrary code execution; device compromise possible

Technical writeup

Two flaws: WebKit (malicious pages execute code), kernel (app could run code with kernel privileges). Apple acknowledged possible active exploitation.

Root cause

WebKit and kernel vulnerabilities.

References