Researchers detailed CVE-2022-32792, a Safari/WebKit JavaScriptCore vulnerability in the B3ReduceStrength optimization phase that mishandled integer range analysis for sign-extension operations such as SExt8, SExt16, and SExt32. The flaw, disclosed after Manfred Paul exploited it at Pwn2Own, caused pre-patch code to treat sign extension as effectively preserving the original range, which could wrongly remove overflow and underflow checks from CheckAdd, CheckSub, and CheckMul operations in JIT-compiled code.
Apple fixed the issue in WebKit by adding IntRange::sExt and updating rangeFor so sign extension is modeled correctly. The published walkthrough showed how the bug could be turned from an Int32 underflow into a bounds-check bypass and out-of-bounds array access, then into corruption of adjacent array metadata; by overlapping double and object arrays, the exploit produced addrof and fakeobj primitives that could be extended to arbitrary read/write and eventual code execution in Safari/WebKit.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
STAR Labs published a detailed analysis of CVE-2022-32792, explaining the root cause in JavaScriptCore's B3ReduceStrength phase and showing how the bug could be turned into out-of-bounds access and object corruption primitives. The write-up included proof-of-concept details demonstrating a path toward arbitrary read/write and eventual code execution in Safari/WebKit.
Apple fixed CVE-2022-32792 in WebKit by adding IntRange::sExt and updating rangeFor so SExt8, SExt16, and SExt32 operations are modeled correctly during optimization. The patch addressed unsafe elimination of overflow and underflow checks that could lead to out-of-bounds writes.
Manfred Paul successfully exploited the WebKit JavaScriptCore vulnerability later tracked as CVE-2022-32792 at Pwn2Own, demonstrating the bug in a real-world contest setting. The exploit exposed a flaw in B3ReduceStrength's handling of sign-extension range analysis.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.