CVE-2022-22594
MEDIUM | Platform: iOS | Changelog
CVE Details
Description
A cross-origin issue in the IndexDB API was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. A website may be able to track sensitive user information.
CVSS 3.1 Score
| Metric | Value |
|---|---|
| Base Score | 6.5 (MEDIUM) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Weakness
References
- Apple Security Advisory
- NVD Entry
- https://support.apple.com/en-us/HT213053 (Release Notes, Vendor Advisory)
- https://support.apple.com/en-us/HT213054 (Release Notes, Vendor Advisory)
- https://support.apple.com/en-us/HT213057 (Release Notes, Vendor Advisory)
- https://support.apple.com/en-us/HT213058 (Release Notes, Vendor Advisory)
- https://support.apple.com/en-us/HT213059 (Release Notes, Vendor Advisory)