CVE-2022-32868
published 2022-09-20CVE-2022-32868: A logic issue was addressed with improved state management. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. A website may be able to track…
PriorityP419medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
EPSS
0.85%
53.9th percentile
A logic issue was addressed with improved state management. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. A website may be able to track users through Safari web extensions.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | ios | >= unspecified < 16 | 16 |
| apple | ios_15.7_and_ipados | — | — |
| apple | ios_and_ipados | >= unspecified < 15.7 | 15.7 |
| apple | ipados | < 15.7 | 15.7 |
| apple | iphone_os | < 15.7 | 15.7 |
| apple | safari | < 16.0 | 16.0 |
| apple | safari | — | — |
| apple | safari | >= unspecified < 16 | 16 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2022-32868: iOS 15.7 and iPadOS 15.7
vendor_apple·2022-09-12·CVSS 4.3
CVE-2022-32868 [MEDIUM] CVE-2022-32868: iOS 15.7 and iPadOS 15.7
Apple Security Update: About the security content of iOS 15.7 and iPadOS 15.7
Product: iOS 15.7 and iPadOS
Version: 15.7
CVE: CVE-2022-32868
Component: Safari Extensions
Impact: A website may be able to track users through Safari web extensions
Description: A logic issue was addressed with improved state management.
Apple
CVE-2022-32868: Safari 16
vendor_apple·2022-09-12·CVSS 4.3
CVE-2022-32868 [MEDIUM] CVE-2022-32868: Safari 16
Apple Security Update: About the security content of Safari 16
Product: Safari
Version: 16
CVE: CVE-2022-32868
Component: Safari Extensions
Impact: A website may be able to track users through Safari web extensions
Description: A logic issue was addressed with improved state management.
Apple
CVE-2022-32868: iOS 16
vendor_apple·2022-09-12·CVSS 4.3
CVE-2022-32868 [MEDIUM] CVE-2022-32868: iOS 16
Apple Security Update: About the security content of iOS 16
Product: iOS
Version: 16
CVE: CVE-2022-32868
Component: Safari Extensions
Impact: A website may be able to track users through Safari web extensions
Description: A logic issue was addressed with improved state management.
GHSA
GHSA-2xc7-wvf3-85p6: A logic issue was addressed with improved state management
ghsa_unreviewed·2022-09-21
CVE-2022-32868 [MEDIUM] GHSA-2xc7-wvf3-85p6: A logic issue was addressed with improved state management
A logic issue was addressed with improved state management. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. A website may be able to track users through Safari web extensions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://seclists.org/fulldisclosure/2022/Oct/39http://seclists.org/fulldisclosure/2022/Oct/40http://seclists.org/fulldisclosure/2022/Oct/50https://support.apple.com/en-us/HT213442https://support.apple.com/en-us/HT213445https://support.apple.com/en-us/HT213446http://seclists.org/fulldisclosure/2022/Oct/39http://seclists.org/fulldisclosure/2022/Oct/40http://seclists.org/fulldisclosure/2022/Oct/50https://support.apple.com/en-us/HT213442https://support.apple.com/en-us/HT213445https://support.apple.com/en-us/HT213446
2022-09-20
Published