CVE-2022-22594: Input Validation
A cross-origin issue existed with the IndexedDB. This was addressed with improved checking of security origins.
Reference: https://webkitgtk.org/security/WSA-2022-0001.html
Other sources
A cross-origin issue in the IndexDB API was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. A website may be able to track sensitive user information.
— MITRE
WebKit Storage. A cross-origin issue in the IndexDB API was addressed with improved input validation.
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2022-22594?
CVE-2022-22594 is a vulnerability in WebKit Storage that involves a cross-origin issue in the IndexDB API.
Which software versions are affected by CVE-2022-22594?
CVE-2022-22594 affects Safari 15.3, watchOS up to 8.4, iOS up to 15.3, iPadOS up to 15.3, tvOS up to 15.3, and macOS Monterey up to 12.2.
How can I fix CVE-2022-22594?
To fix CVE-2022-22594, make sure to update your affected software to the recommended versions provided by Apple.
Where can I find more information about CVE-2022-22594?
You can find more information about CVE-2022-22594 on Apple's support page. Here are some relevant references: [reference1], [reference2], [reference3].
What is the CWE classification of CVE-2022-22594?
The CWE classification of CVE-2022-22594 is CWE-20, which stands for Improper Input Validation.