CVE-2022-22589 is a validation issue in Apple products, including iOS, iPadOS, watchOS, tvOS, Safari, and macOS, that could allow for arbitrary JavaScript execution. This vulnerability, rated Medium severity (CVSS 6.1), requires user interaction (UI:R) and involves processing a maliciously crafted mail message. While it has a low EPSS score and no known exploit intelligence or community discussion, indicating a low current exploitation risk, affected systems should be updated to iOS/iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, or macOS Monterey 12.2 to mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 15.3CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
< 15.3CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 15.3CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
>= 10.15, < 10.15.7CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
10.15.7CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.15.7:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.