An Autopsy on a Zombie In-the-Wild 0-day
ID: 839ea871-a1ae-5687-b93b-69de88592b0e
STIX ID: report--839ea871-a1ae-5687-b93b-69de88592b0e
Feed Name: Google Project Zero
Threat Score
Project Zero details the lifecycle of CVE-2022-22620, a WebKit/Safari use-after-free that was correctly fixed in 2013, accidentally reintroduced during large refactoring in 2016, and ultimately observed exploited in the wild in 2022; the post explains the code changes, test coverage, trigger path (loadInSameDocument → blur → replaceState), and lessons about regression risks during refactoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
