CVE-2022-22637
published 2022-09-23CVE-2022-22637: A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4…
PriorityP340high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.63%
46.2th percentile
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. A malicious website may cause unexpected cross-origin behavior.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_15.4_and_ipados | — | — |
| apple | ipad_os | < 15.4 | 15.4 |
| apple | iphone_os | < 15.4 | 15.4 |
| apple | macos | >= 12.0 < 12.3 | 12.3 |
| apple | macos_monterey | — | — |
| apple | safari | < 15.4 | 15.4 |
| apple | safari | — | — |
| apple | safari | >= unspecified < 15.4 | 15.4 |
| apple | tvos | < 15.4 | 15.4 |
| apple | tvos | — | — |
| apple | tvos | >= unspecified < 15.4 | 15.4 |
| apple | tvos | >= unspecified < 12.3 | 12.3 |
| apple | watchos | < 8.5 | 8.5 |
| apple | watchos | — | — |
| apple | watchos | >= unspecified < 8.5 | 8.5 |
| debian | webkit2gtk | < webkit2gtk 2.34.4-1 (bookworm) | webkit2gtk 2.34.4-1 (bookworm) |
| debian | wpewebkit | < webkit2gtk 2.34.4-1 (bookworm) | webkit2gtk 2.34.4-1 (bookworm) |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
WebKitGTK vulnerabilities
vendor_ubuntu·2022-04-28
CVE-2022-22624 WebKitGTK vulnerabilities
Title: WebKitGTK vulnerabilities
Summary: Several security issues were fixed in WebKitGTK.
A large number of security issues were discovered in the WebKitGTK Web and
JavaScript engines. If a user were tricked into viewing a malicious
website, a remote attacker could exploit a variety of issues related to web
browser security, including cross-site scripting attacks, denial of service
attacks, and arbitrary code execution.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use WebKitGTK, such as Epiphany, to make all the necessary changes.
Red Hat
webkitgtk: logic issue was addressed with improved state management
vendor_redhat·2022-04-08·CVSS 8.8
CVE-2022-22637 [HIGH] webkitgtk: logic issue was addressed with improved state management
webkitgtk: logic issue was addressed with improved state management
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. A malicious website may cause unexpected cross-origin behavior.
A logic issue was found in WebKitGTK and WPE WebKit. This flaw allows a remote attacker to process unexpected cross-origin attacks.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Out of support scope
Package: webkitgtk3 (Red Hat Enterprise Linux 7) - Out of support scope
Package: webkit2gtk3 (Red Hat Enterprise Linux 9) - Not affected
Apple
CVE-2022-22637: Safari 15.4
vendor_apple·2022-03-15·CVSS 8.8
CVE-2022-22637 [HIGH] CVE-2022-22637: Safari 15.4
Apple Security Update: About the security content of Safari 15.4
Product: Safari
Version: 15.4
CVE: CVE-2022-22637
Component: WebKit
Impact: A malicious website may cause unexpected cross-origin behavior
Description: A logic issue was addressed with improved state management.
Apple
CVE-2022-22637: watchOS 8.5
vendor_apple·2022-03-14·CVSS 8.8
CVE-2022-22637 [HIGH] CVE-2022-22637: watchOS 8.5
Apple Security Update: About the security content of watchOS 8.5
Product: watchOS
Version: 8.5
CVE: CVE-2022-22637
Component: WebKit
Impact: A malicious website may cause unexpected cross-origin behavior
Description: A logic issue was addressed with improved state management.
Apple
CVE-2022-22637: macOS Monterey 12.3
vendor_apple·2022-03-14·CVSS 8.8
CVE-2022-22637 [HIGH] CVE-2022-22637: macOS Monterey 12.3
Apple Security Update: About the security content of macOS Monterey 12.3
Product: macOS Monterey
Version: 12.3
CVE: CVE-2022-22637
Component: WebKit
Impact: A malicious website may cause unexpected cross-origin behavior
Description: A logic issue was addressed with improved state management.
Apple
CVE-2022-22637: tvOS 15.4
vendor_apple·2022-03-14·CVSS 8.8
CVE-2022-22637 [HIGH] CVE-2022-22637: tvOS 15.4
Apple Security Update: About the security content of tvOS 15.4
Product: tvOS
Version: 15.4
CVE: CVE-2022-22637
Component: WebKit
Impact: A malicious website may cause unexpected cross-origin behavior
Description: A logic issue was addressed with improved state management.
Apple
CVE-2022-22637: iOS 15.4 and iPadOS 15.4
vendor_apple·2022-03-14·CVSS 8.8
CVE-2022-22637 [HIGH] CVE-2022-22637: iOS 15.4 and iPadOS 15.4
Apple Security Update: About the security content of iOS 15.4 and iPadOS 15.4
Product: iOS 15.4 and iPadOS
Version: 15.4
CVE: CVE-2022-22637
Component: WebKit
Impact: A malicious website may cause unexpected cross-origin behavior
Description: A logic issue was addressed with improved state management.
Debian
CVE-2022-22637: webkit2gtk - A logic issue was addressed with improved state management. This issue is fixed ...
vendor_debian·2022·CVSS 8.8
CVE-2022-22637 [HIGH] CVE-2022-22637: webkit2gtk - A logic issue was addressed with improved state management. This issue is fixed ...
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. A malicious website may cause unexpected cross-origin behavior.
Scope: local
bookworm: resolved (fixed in 2.34.4-1)
bullseye: resolved (fixed in 2.34.4-1~deb11u1)
forky: resolved (fixed in 2.34.4-1)
sid: resolved (fixed in 2.34.4-1)
trixie: resolved (fixed in 2.34.4-1)
GHSA
GHSA-p38h-v883-px7v: A logic issue was addressed with improved state management
ghsa_unreviewed·2022-09-25
CVE-2022-22637 [HIGH] CWE-346 GHSA-p38h-v883-px7v: A logic issue was addressed with improved state management
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. A malicious website may cause unexpected cross-origin behavior.
OSV
CVE-2022-22637: A logic issue was addressed with improved state management
osv·2022-09-23·CVSS 8.8
CVE-2022-22637 [HIGH] CVE-2022-22637: A logic issue was addressed with improved state management
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. A malicious website may cause unexpected cross-origin behavior.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://support.apple.com/en-us/HT213182https://support.apple.com/en-us/HT213183https://support.apple.com/en-us/HT213186https://support.apple.com/en-us/HT213187https://support.apple.com/en-us/HT213193https://support.apple.com/en-us/HT213182https://support.apple.com/en-us/HT213183https://support.apple.com/en-us/HT213186https://support.apple.com/en-us/HT213187https://support.apple.com/en-us/HT213193
2022-09-23
Published