First published: Tue Mar 08 2022(Updated: )
A cookie management issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Big Sur 11.6.5. Processing maliciously crafted web content may disclose sensitive user information.
Credit: Prakash @1lastBr3ath Threat Nix product-security@apple.com product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iTunes for Windows | <12.12.3 | 12.12.3 |
Apple tvOS | <15.4 | 15.4 |
Apple macOS Big Sur | <11.6.5 | 11.6.5 |
Apple Catalina | ||
Apple watchOS | <8.5 | 8.5 |
Apple macOS Monterey | <12.3 | 12.3 |
Apple iOS | <15.4 | 15.4 |
Apple iPadOS | <15.4 | 15.4 |
Apple Mac OS X | >=10.15<10.15.7 | |
Apple Mac OS X | =10.15.7 | |
Apple Mac OS X | =10.15.7-security_update_2020 | |
Apple Mac OS X | =10.15.7-security_update_2020-001 | |
Apple Mac OS X | =10.15.7-security_update_2020-005 | |
Apple Mac OS X | =10.15.7-security_update_2020-007 | |
Apple Mac OS X | =10.15.7-security_update_2021-001 | |
Apple Mac OS X | =10.15.7-security_update_2021-002 | |
Apple Mac OS X | =10.15.7-security_update_2021-003 | |
Apple Mac OS X | =10.15.7-security_update_2021-006 | |
Apple Mac OS X | =10.15.7-security_update_2021-007 | |
Apple Mac OS X | =10.15.7-security_update_2021-008 | |
Apple Mac OS X | =10.15.7-security_update_2022-001 | |
Apple Mac OS X | =10.15.7-security_update_2022-002 | |
Apple Mac OS X | =10.15.7-supplemental_update | |
Apple macOS | >=11.0<11.6.5 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
The vulnerability ID of this issue is CVE-2022-22662.
The severity of CVE-2022-22662 is medium with a severity value of 6.5.
CVE-2022-22662 affects multiple software versions including tvOS 15.4, watchOS 8.5, iTunes for Windows 12.12.3, macOS Big Sur 11.6.5, macOS Monterey 12.3, iOS 15.4, iPadOS 15.4, and others.
This vulnerability can be fixed by installing Security Update 2022-003 Catalina and macOS Big Sur 11.6.5.
CVE-2022-22662 allows processing maliciously crafted web content to disclose sensitive user information.