CVE Vulnerabilities

CVE-2022-43454

Double Free

Published: Mar 10, 2025 | Modified: Mar 24, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A double free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An app may be able to execute arbitrary code with kernel privileges.

Weakness

The product calls free() twice on the same memory address.

Affected Software

NameVendorStart VersionEnd Version
IpadosApple*16.2 (excluding)
Iphone_osApple*16.2 (excluding)
MacosApple*13.1 (excluding)
TvosApple*16.2 (excluding)
WatchosApple*9.2 (excluding)

Potential Mitigations

References