8.8

CVE-2022-22637

A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. A malicious website may cause unexpected cross-origin behavior.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ Safari Version < 15.4
Apple ≫ iPad OS Version < 15.4
Apple ≫ iPhone OS Version < 15.4
Apple ≫ macOS Version >= 12.0 < 12.3
Apple ≫ tvOS Version < 15.4
Apple ≫ watchOS Version < 8.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.65% 0.477
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA-ADP 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-346 Origin Validation Error

The product does not properly verify that the source of data or communication is valid.

https://support.apple.com/en-us/HT213182
Vendor Advisory
https://support.apple.com/en-us/HT213193
Vendor Advisory
https://support.apple.com/en-us/HT213183
Vendor Advisory
https://support.apple.com/en-us/HT213186
Vendor Advisory
https://support.apple.com/en-us/HT213187
Vendor Advisory