CVE-2022-22589: Input Validation
A flaw was found in WebKitGTK. A validation issue was addressed with improved input sanitization.
Reference: https://webkitgtk.org/security/WSA-2022-0002.html
Other sources
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing a maliciously crafted mail message may lead to running arbitrary javascript.
— MITRE
apache. Multiple issues were addressed by updating apache to version 2.4.53.
— Apple
AppKit. A logic issue was addressed with improved validation.
— Apple
AppleAVD. An out-of-bounds write issue was addressed with improved bounds checking.
— Apple
AppleEvents. A use after free issue was addressed with improved memory management.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2021-44224
- CVE-2021-44790
- CVE-2022-22719
- CVE-2022-22720
- CVE-2022-22721
- CVE-2022-22665
- CVE-2022-22675
- CVE-2022-22630
- CVE-2022-26751
- CVE-2022-26698
- CVE-2022-26697
- CVE-2022-22663
- CVE-2022-26721
- CVE-2022-26722
- CVE-2022-26763
- CVE-2022-22674
- CVE-2022-26720
- CVE-2022-26770
- CVE-2022-26756
- CVE-2022-26769
- CVE-2022-26748
- CVE-2022-26768
- CVE-2022-26714
- CVE-2022-26757
- CVE-2021-30946
- CVE-2022-26767
- CVE-2022-26706
- CVE-2022-32882
- CVE-2022-32790
- CVE-2022-26776
- CVE-2022-0778
- CVE-2022-23308
- CVE-2022-32794
- CVE-2022-26712
- CVE-2022-26746
- CVE-2022-26731
- CVE-2022-26766
- CVE-2022-26718
- CVE-2022-26723
- CVE-2022-26715
- CVE-2022-26728
- CVE-2022-26726
- CVE-2022-26755
- CVE-2021-4136
- CVE-2021-4166
- CVE-2021-4173
- CVE-2021-4187
- CVE-2021-4192
- CVE-2021-4193
- CVE-2021-46059
- CVE-2022-0128
- CVE-2022-22589
- CVE-2022-26745
- CVE-2022-26761
- CVE-2022-0530
- CVE-2018-25032
- CVE-2021-45444
- CVE-2022-22584
- CVE-2022-22578
- CVE-2022-22585
- CVE-2022-22593
- CVE-2022-22579
- CVE-2022-22590
- CVE-2022-22592
- CVE-2022-22594
- CVE-2022-22631
- CVE-2022-22648
- CVE-2022-22627
- CVE-2022-22626
- CVE-2022-22625
- CVE-2022-22597
- CVE-2022-22616
- CVE-2022-26691
- CVE-2022-46706
- CVE-2022-22661
- CVE-2022-22613
- CVE-2022-22615
- CVE-2022-22614
- CVE-2022-22638
- CVE-2022-22647
- CVE-2022-22656
- CVE-2022-22672
- CVE-2022-26688
- CVE-2022-22617
- CVE-2022-22650
- CVE-2022-22662
- CVE-2022-22582
- CVE-2022-26775
- CVE-2022-26727
- CVE-2022-22586
- CVE-2022-22591
- CVE-2022-22587
- CVE-2022-22646
- CVE-2022-22676
- CVE-2022-22583
Frequently Asked Questions
What is CVE-2022-22589?
CVE-2022-22589 is a vulnerability in WebKit that allows for arbitrary JavaScript execution when processing a maliciously crafted mail message.
Which software versions are affected by CVE-2022-22589?
CVE-2022-22589 affects iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, and macOS Monterey 12.2.
What is the severity of CVE-2022-22589?
CVE-2022-22589 has a severity rating of 6.1, which is considered medium.
How can I fix CVE-2022-22589?
To fix CVE-2022-22589, you need to update to the fixed versions of the affected software. For example, update to iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, or macOS Monterey 12.2.
Where can I find more information about CVE-2022-22589?
You can find more information about CVE-2022-22589 on the Apple Support website. Here are some references to get you started: [Link 1](https://support.apple.com/en-us/HT213054), [Link 2](https://support.apple.com/en-us/HT213255), [Link 3](https://support.apple.com/en-us/HT213053).