First published: Wed Jan 26 2022(Updated: )
WebKit Storage. A cross-origin issue in the IndexDB API was addressed with improved input validation.
Credit: Martin Bajanik FingerprintJSMartin Bajanik FingerprintJSMartin Bajanik FingerprintJSMartin Bajanik FingerprintJSMartin Bajanik FingerprintJS product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | <15.3 | 15.3 |
Apple tvOS | <15.3 | 15.3 |
Apple watchOS | <8.4 | 8.4 |
Apple macOS Monterey | <12.2 | 12.2 |
Apple iOS | <15.3 | 15.3 |
Apple iPadOS | <15.3 | 15.3 |
Apple Safari | <15.3 | |
Apple iPadOS | <15.3 | |
Apple iPhone OS | <15.3 | |
Apple macOS | <12.2 | |
Apple tvOS | <15.3 | |
Apple watchOS | <8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-22594 is a vulnerability in WebKit Storage that involves a cross-origin issue in the IndexDB API.
CVE-2022-22594 affects Safari 15.3, watchOS up to 8.4, iOS up to 15.3, iPadOS up to 15.3, tvOS up to 15.3, and macOS Monterey up to 12.2.
To fix CVE-2022-22594, make sure to update your affected software to the recommended versions provided by Apple.
You can find more information about CVE-2022-22594 on Apple's support page. Here are some relevant references: [reference1], [reference2], [reference3].
The CWE classification of CVE-2022-22594 is CWE-20, which stands for Improper Input Validation.