
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-22637 is a security vulnerability discovered in Apple's WebKit browser engine that was disclosed and patched in March 2022. The vulnerability affects multiple Apple products including macOS Monterey, Safari, watchOS, iOS, iPadOS, and tvOS. It was identified as a logic issue in WebKit that could allow a malicious website to cause unexpected cross-origin behavior (Apple Support, NVD).
The vulnerability is classified as a logic issue in WebKit's state management system. It received a CVSS v3.1 Base Score of 8.8 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. The issue was discovered by Tom McKee of Google and tracked as WebKit Bugzilla: 235294 (NVD).
When exploited, this vulnerability could allow a malicious website to cause unexpected cross-origin behavior, potentially leading to unauthorized access to sensitive information or resources across different web origins (Apple Support).
Apple addressed this vulnerability by improving state management in WebKit. The fix was released in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, and tvOS 15.4. Users are advised to update their devices to these versions or later to mitigate the vulnerability (Apple Support).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."