CVE-2022-26717 is a use-after-free vulnerability in WebKit's WebGL implementation affecting Safari and related Apple platforms. The flaw occurs in WebGL2 Transform Feedback handling in ANGLE's Metal backend: the transform-feedback buffer-emulation path can access a BufferMtl object's current buffer after it has been freed. A crafted WebGL sequence can bind a transform-feedback buffer, delete it, and invoke drawArrays, causing access to freed memory. Processing maliciously crafted web content may result in arbitrary code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small browser exploit/PoC set for CVE-2022-26717, identified in the README as a Safari WebGL XFB (transform feedback) use-after-free vulnerability. It contains three files: a minimal README, poc.html, and exploit.html. There is no external framework involved. poc.html is the simpler trigger. It creates a WebGL2 context, compiles/link shaders, configures transform feedback varyings, allocates a buffer for transform feedback, binds it, unbinds transform feedback, then deletes the buffer and immediately reuses the freed allocation via gl.bufferData on another buffer before calling gl.drawArrays. This demonstrates the core bug: use of a freed buffer object during draw processing. exploit.html builds on the same primitive and adds exploitation-oriented logic. It defines helper routines for float/qword conversion, garbage collection pressure, JIT warm-up, and large-scale array spraying. The trigger() function performs the same free-and-reclaim sequence using controlled typed-array data. The exploit() function sprays many JavaScript arrays, repeatedly triggers the bug, scans for a corrupted sprayed array by checking for a sentinel-like value (0x1010000000000), then mutates array metadata to locate a fake array of length 0x1338. Once found, it starts constructing fake object/array state by copying a valid JSCell/structure value and adjusting internal pointers. Comments explicitly mention 'fakeobj & addrof stuff', indicating the exploit is intended to progress toward standard JavaScriptCore exploitation primitives. No network beacons, remote C2, hardcoded IPs, or exfiltration endpoints are present. The only URL is Apple's patch advisory in the README. The exploit is entirely client-side and browser-local: it must be opened in a vulnerable Safari/WebKit environment with WebGL2 support. Overall, this is a real exploit repository containing both a crash/trigger PoC and a more advanced but still incomplete exploitation stage for browser memory corruption, best classified as a proof-of-concept rather than a weaponized exploit.
This repository contains a proof-of-concept exploit for CVE-2022-26717, a use-after-free vulnerability in Safari's WebGL XFB (Transform Feedback) implementation. The repository consists of three files: a README.md with credits and patch information, 'exploit.html' (the main exploit), and 'poc.html' (a minimal proof-of-concept). Both HTML files contain JavaScript code that manipulates WebGL2 contexts and ArrayBuffer objects to trigger the vulnerability. The exploit uses heap spraying and buffer manipulation to achieve a use-after-free condition, which could potentially be leveraged for arbitrary code execution. The exploit is intended to be opened in a vulnerable version of Safari on macOS. No external network endpoints or IP addresses are present; the attack vector is browser-based, requiring the victim to visit a malicious HTML page.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A use-after-free vulnerability in WebKitGTK that can lead to arbitrary code execution.
Unknown
Unknown
A vulnerability addressed by the listed product release; technical details are not provided.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.