CVE-2022-22620, also known as Zombie, is a use-after-free vulnerability in WebKit. The issue resulted from a regressed fix: it was originally fixed in 2013, but the patch regressed in 2016. Processing attacker-crafted web content can trigger the memory-safety flaw and lead to arbitrary code execution. Apple reported awareness that the vulnerability may have been actively exploited.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept (POC) exploit for CVE-2022-22620, a use-after-free vulnerability in Apple's Safari (WebKit) browser engine. The repository contains three files: a LICENSE (GPLv3), a README.md with a brief description and reference link, and an 'index.html' file containing the exploit code. The exploit is implemented in JavaScript within the HTML file and works by manipulating the browser's history and focus/blur events on DOM elements to trigger the vulnerability. The user is expected to open 'index.html' in a vulnerable version of Safari to test the exploit. No external network endpoints or IP addresses are present; the exploit is self-contained and targets the browser's internal logic. The repository serves as a demonstration of the vulnerability and does not include weaponized payloads or post-exploitation code.
This repository contains a proof-of-concept (PoC) exploit for CVE-2022-22620, a use-after-free vulnerability in Safari/WebKit. The main file, 'CVE-2022-22620_infoleak_exploit.html', is a standalone HTML+JavaScript exploit that, when opened in a vulnerable browser, manipulates browser history and DOM events to trigger the vulnerability and leak the address of a JavaScript object (infoleak). The exploit is based on a Google Project Zero PoC and is tested on WebKitGTK 2.34.3 (Ubuntu 64-bit). The README provides context and references but no additional code. There are no hardcoded IPs or network endpoints beyond references to documentation and the tested WebKitGTK version. The exploit demonstrates an infoleak primitive and is intended for research and demonstration purposes.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Use-after-free in webkitgtk allowing arbitrary code execution through malicious web content.
A WebKit vulnerability known as 'Zombie', originally fixed in 2013 but regressed in 2016, exploited in the wild in 2022.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.