CVE-2022-22589
published 2022-03-18CVE-2022-22589: A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS…
PriorityP431medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.97%
78.1th percentile
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing a maliciously crafted mail message may lead to running arbitrary javascript.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_15.3_and_ipados | — | — |
| apple | ios_and_ipados | >= unspecified < 15.3 | 15.3 |
| apple | ipados | < 15.3 | 15.3 |
| apple | iphone_os | < 15.3 | 15.3 |
| apple | mac_os_x | — | — |
| apple | mac_os_x | >= 10.15 < 10.15.7 | 10.15.7 |
| apple | macos | >= 11.0 < 11.6.6 | 11.6.6 |
| apple | macos | >= 12.0.0 < 12.2 | 12.2 |
| apple | macos | >= unspecified < 12.2 | 12.2 |
| apple | macos_big_sur | — | — |
| apple | macos_monterey | — | — |
| apple | safari | < 15.3 | 15.3 |
| apple | safari | — | — |
| apple | security_update_2022-003_catalina | — | — |
| apple | security_update_2022-004_catalina | — | — |
| apple | tvos | < 15.3 | 15.3 |
| apple | tvos | — | — |
| apple | tvos | >= unspecified < 15.3 | 15.3 |
| apple | watchos | < 8.4 | 8.4 |
| apple | watchos | — | — |
| apple | watchos | >= unspecified < 8.4 | 8.4 |
| debian | webkit2gtk | < webkit2gtk 2.34.5-1 (bookworm) | webkit2gtk 2.34.5-1 (bookworm) |
| debian | wpewebkit | < webkit2gtk 2.34.5-1 (bookworm) | webkit2gtk 2.34.5-1 (bookworm) |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2022-22589: macOS Big Sur 11.6.6
vendor_apple·2022-05-16·CVSS 6.1
CVE-2022-22589 [MEDIUM] CVE-2022-22589: macOS Big Sur 11.6.6
Apple Security Update: About the security content of macOS Big Sur 11.6.6
Product: macOS Big Sur
Version: 11.6.6
CVE: CVE-2022-22589
Component: WebKit
Impact: Processing a maliciously crafted mail message may lead to running arbitrary javascript
Description: A validation issue was addressed with improved input sanitization.
Apple
CVE-2022-22589: Security Update 2022-004 Catalina
vendor_apple·2022-05-16·CVSS 6.1
CVE-2022-22589 [MEDIUM] CVE-2022-22589: Security Update 2022-004 Catalina
Apple Security Update: About the security content of Security Update 2022-004 Catalina
Product: Security Update 2022-004 Catalina
CVE: CVE-2022-22589
Component: WebKit
Impact: Processing a maliciously crafted mail message may lead to running arbitrary javascript
Description: A validation issue was addressed with improved input sanitization.
Apple
CVE-2022-22589: Security Update 2022-003 Catalina
vendor_apple·2022-03-14·CVSS 6.1
CVE-2022-22589 [MEDIUM] CVE-2022-22589: Security Update 2022-003 Catalina
Apple Security Update: About the security content of Security Update 2022-003 Catalina
Product: Security Update 2022-003 Catalina
CVE: CVE-2022-22589
Component: WebKit
Impact: Processing a maliciously crafted mail message may lead to running arbitrary javascript
Description: A validation issue was addressed with improved input sanitization.
Ubuntu
WebKitGTK vulnerabilities
vendor_ubuntu·2022-02-28
CVE-2022-22589 WebKitGTK vulnerabilities
Title: WebKitGTK vulnerabilities
Summary: Several security issues were fixed in WebKitGTK.
A large number of security issues were discovered in the WebKitGTK Web and
JavaScript engines. If a user were tricked into viewing a malicious
website, a remote attacker could exploit a variety of issues related to web
browser security, including cross-site scripting attacks, denial of service
attacks, and arbitrary code execution.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use WebKitGTK, such as Epiphany, to make all the necessary changes.
Red Hat
webkitgtk: Processing a maliciously crafted mail message may lead to running arbitrary javascript
vendor_redhat·2022-02-09·CVSS 6.1
CVE-2022-22589 [MEDIUM] CWE-1173 webkitgtk: Processing a maliciously crafted mail message may lead to running arbitrary javascript
webkitgtk: Processing a maliciously crafted mail message may lead to running arbitrary javascript
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing a maliciously crafted mail message may lead to running arbitrary javascript.
A vulnerability was found in WebKitGTK. The vulnerability exists due to improper input validation in WebKit when processing email messages. This flaw allows a remote attacker to trick the victim into opening a specially crafted email message and execute arbitrary JavaScript code.
Statement: Red Hat Enterprise Linux 6, 7, 8, and 9 are affected because the code-base is affected by this vulnerability.
Red Hat Product Security has rated
Apple
CVE-2022-22589: iOS 15.3 and iPadOS 15.3
vendor_apple·2022-01-26·CVSS 6.1
CVE-2022-22589 [MEDIUM] CVE-2022-22589: iOS 15.3 and iPadOS 15.3
Apple Security Update: About the security content of iOS 15.3 and iPadOS 15.3
Product: iOS 15.3 and iPadOS
Version: 15.3
CVE: CVE-2022-22589
Component: WebKit
Impact: Processing a maliciously crafted mail message may lead to running arbitrary javascript
Description: A validation issue was addressed with improved input sanitization.
Apple
CVE-2022-22589: Safari 15.3
vendor_apple·2022-01-26·CVSS 6.1
CVE-2022-22589 [MEDIUM] CVE-2022-22589: Safari 15.3
Apple Security Update: About the security content of Safari 15.3
Product: Safari
Version: 15.3
CVE: CVE-2022-22589
Component: WebKit
Impact: Processing a maliciously crafted mail message may lead to running arbitrary javascript
Description: A validation issue was addressed with improved input sanitization.
Apple
CVE-2022-22589: macOS Monterey 12.2
vendor_apple·2022-01-26·CVSS 6.1
CVE-2022-22589 [MEDIUM] CVE-2022-22589: macOS Monterey 12.2
Apple Security Update: About the security content of macOS Monterey 12.2
Product: macOS Monterey
Version: 12.2
CVE: CVE-2022-22589
Component: WebKit
Impact: Processing a maliciously crafted mail message may lead to running arbitrary javascript
Description: A validation issue was addressed with improved input sanitization.
Apple
CVE-2022-22589: tvOS 15.3
vendor_apple·2022-01-26·CVSS 6.1
CVE-2022-22589 [MEDIUM] CVE-2022-22589: tvOS 15.3
Apple Security Update: About the security content of tvOS 15.3
Product: tvOS
Version: 15.3
CVE: CVE-2022-22589
Component: WebKit
Impact: Processing a maliciously crafted mail message may lead to running arbitrary javascript
Description: A validation issue was addressed with improved input sanitization.
Apple
CVE-2022-22589: watchOS 8.4
vendor_apple·2022-01-26·CVSS 6.1
CVE-2022-22589 [MEDIUM] CVE-2022-22589: watchOS 8.4
Apple Security Update: About the security content of watchOS 8.4
Product: watchOS
Version: 8.4
CVE: CVE-2022-22589
Component: WebKit
Impact: Processing a maliciously crafted mail message may lead to running arbitrary javascript
Description: A validation issue was addressed with improved input sanitization.
Debian
CVE-2022-22589: webkit2gtk - A validation issue was addressed with improved input sanitization. This issue is...
vendor_debian·2022·CVSS 6.1
CVE-2022-22589 [MEDIUM] CVE-2022-22589: webkit2gtk - A validation issue was addressed with improved input sanitization. This issue is...
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing a maliciously crafted mail message may lead to running arbitrary javascript.
Scope: local
bookworm: resolved (fixed in 2.34.5-1)
bullseye: resolved (fixed in 2.34.6-1~deb11u1)
forky: resolved (fixed in 2.34.5-1)
sid: resolved (fixed in 2.34.5-1)
trixie: resolved (fixed in 2.34.5-1)
GHSA
GHSA-4c33-fwgf-qv6r: A validation issue was addressed with improved input sanitization
ghsa_unreviewed·2022-03-19
CVE-2022-22589 [MEDIUM] CWE-20 GHSA-4c33-fwgf-qv6r: A validation issue was addressed with improved input sanitization
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing a maliciously crafted mail message may lead to running arbitrary javascript.
OSV
CVE-2022-22589: A validation issue was addressed with improved input sanitization
osv·2022-03-18·CVSS 6.1
CVE-2022-22589 [MEDIUM] CVE-2022-22589: A validation issue was addressed with improved input sanitization
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing a maliciously crafted mail message may lead to running arbitrary javascript.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://seclists.org/fulldisclosure/2022/May/33http://seclists.org/fulldisclosure/2022/May/35https://security.gentoo.org/glsa/202208-39https://support.apple.com/en-us/HT213053https://support.apple.com/en-us/HT213054https://support.apple.com/en-us/HT213057https://support.apple.com/en-us/HT213058https://support.apple.com/en-us/HT213059https://support.apple.com/kb/HT213185https://support.apple.com/kb/HT213255https://support.apple.com/kb/HT213256http://seclists.org/fulldisclosure/2022/May/33http://seclists.org/fulldisclosure/2022/May/35https://security.gentoo.org/glsa/202208-39https://support.apple.com/en-us/HT213053https://support.apple.com/en-us/HT213054https://support.apple.com/en-us/HT213057https://support.apple.com/en-us/HT213058https://support.apple.com/en-us/HT213059https://support.apple.com/kb/HT213185https://support.apple.com/kb/HT213255https://support.apple.com/kb/HT213256
2022-03-18
Published