v14.1 [Dec 16, 2022]
ImageIO:
- Available for: Windows 10 and later via the Microsoft Store.
- Impact: Processing a maliciously crafted file may lead to arbitrary code execution.
- Description: An out-of-bounds write issue was addressed with improved input validation.
- CVE-2022-46693: Mickey Jin (@patch1t).
WebKit:
- Available for: Windows 10 and later via the Microsoft Store.
- Impact: Processing maliciously crafted web content may bypass Same Origin Policy.
- Description: A logic issue was addressed with improved state management.
- WebKit Bugzilla: 246783
CVE-2022-46692: KirtiKumar Anandrao Ramchandani.
WebKit:
- Available for: Windows 10 and later via the Microsoft Store.
- Impact: Processing maliciously crafted web content may disclose sensitive user information.
- Description: A logic issue was addressed with improved checks.
- CVE-2022-46698: Dohyun Lee (@l33d0hyun) of SSD Secure Disclosure Labs & DNSLab, Korea Univ.
v7.9 [Dec 5, 2018]
Multiple memory corruption issues were addressed with improved memory handling.
v6.2 [Mar 28, 2017]
APNs Server
Available for: Windows 7 and later
Impact: An attacker in a privileged network position can track a user's activity
Description: A client certificate was sent in plaintext. This issue was addressed through improved certificate handling.
CVE-2017-2383: Matthias Wachs and Quirin Scheitle of Technical University Munich (TUM)
libxslt
Available for: Windows 7 and later
Impact: Multiple vulnerabilities in libxslt
Description: Multiple memory corruption issues were addressed through improved memory handling.
CVE-2017-5029: Holger Fuhrmannek
WebKit
Available for: Windows 7 and later
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed through improved memory handling.
CVE-2017-2463: Kai Kang (4B5F5F4B) of Tencent's Xuanwu Lab (tencent.com) working with Trend Micro's Zero Day Initiative
WebKit
Available for: Windows 7 and later
Impact: Processing maliciously crafted web content may exfiltrate data cross-origin
Description: A validation issue existed in element handling. This issue was addressed through improved validation.
CVE-2017-2479: lokihardt of Google Project Zero
CVE-2017-2480: lokihardt of Google Project Zero
v5.0 [Aug 27, 2015]
May include unspecified updates, enhancements, or bug fixes.