CVE-2022-32891
published 2023-02-27CVE-2022-32891: The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchOS 9, iOS 16. Visiting a website that frames malicious…
PriorityP425medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.70%
49.2th percentile
The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchOS 9, iOS 16. Visiting a website that frames malicious content may lead to UI spoofing.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | ios | >= unspecified < 16 | 16 |
| apple | iphone_os | < 16.0 | 16.0 |
| apple | safari | < 16.0 | 16.0 |
| apple | safari | — | — |
| apple | safari | >= unspecified < 16 | 16 |
| apple | tvos | < 16.0 | 16.0 |
| apple | tvos | — | — |
| apple | watchos | < 9.0 | 9.0 |
| apple | watchos | >= unspecified < 9 | 9 |
| apple | watchos | >= unspecified < 16 | 16 |
| apple | watchos_9 | — | — |
| debian | webkit2gtk | < webkit2gtk 2.36.6-1 (bookworm) | webkit2gtk 2.36.6-1 (bookworm) |
| debian | wpewebkit | < webkit2gtk 2.36.6-1 (bookworm) | webkit2gtk 2.36.6-1 (bookworm) |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
webkitgtk: UI spoofing while Visiting a website that frames malicious content
vendor_redhat·2022-09-12·CVSS 6.1
CVE-2022-32891 [MEDIUM] CWE-120 webkitgtk: UI spoofing while Visiting a website that frames malicious content
webkitgtk: UI spoofing while Visiting a website that frames malicious content
The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchOS 9, iOS 16. Visiting a website that frames malicious content may lead to UI spoofing.
A vulnerability was found in webkitgtk, where an issue was addressed with improved UI handling. Visiting a website that frames malicious content may lead to UI spoofing.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Out of support scope
Package: webkitgtk3 (Red Hat Enterprise Linux 7) - Out of support scope
Apple
CVE-2022-32891: tvOS 16
vendor_apple·2022-09-12·CVSS 6.1
CVE-2022-32891 [MEDIUM] CVE-2022-32891: tvOS 16
Apple Security Update: About the security content of tvOS 16
Product: tvOS
Version: 16
CVE: CVE-2022-32891
Component: WebKit
Impact: Visiting a website that frames malicious content may lead to UI spoofing
Description: The issue was addressed with improved UI handling.
Apple
CVE-2022-32891: watchOS 9
vendor_apple·2022-09-12·CVSS 6.1
CVE-2022-32891 [MEDIUM] CVE-2022-32891: watchOS 9
Apple Security Update: About the security content of watchOS 9
Product: watchOS 9
CVE: CVE-2022-32891
Component: WebKit
Impact: Visiting a website that frames malicious content may lead to UI spoofing
Description: The issue was addressed with improved UI handling.
Apple
CVE-2022-32891: iOS 16
vendor_apple·2022-09-12·CVSS 6.1
CVE-2022-32891 [MEDIUM] CVE-2022-32891: iOS 16
Apple Security Update: About the security content of iOS 16
Product: iOS
Version: 16
CVE: CVE-2022-32891
Component: WebKit
Impact: Visiting a website that frames malicious content may lead to UI spoofing
Description: The issue was addressed with improved UI handling.
Apple
CVE-2022-32891: Safari 16
vendor_apple·2022-09-12·CVSS 6.1
CVE-2022-32891 [MEDIUM] CVE-2022-32891: Safari 16
Apple Security Update: About the security content of Safari 16
Product: Safari
Version: 16
CVE: CVE-2022-32891
Component: WebKit
Impact: Visiting a website that frames malicious content may lead to UI spoofing
Description: The issue was addressed with improved UI handling.
Debian
CVE-2022-32891: webkit2gtk - The issue was addressed with improved UI handling. This issue is fixed in Safari...
vendor_debian·2022·CVSS 6.1
CVE-2022-32891 [MEDIUM] CVE-2022-32891: webkit2gtk - The issue was addressed with improved UI handling. This issue is fixed in Safari...
The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchOS 9, iOS 16. Visiting a website that frames malicious content may lead to UI spoofing.
Scope: local
bookworm: resolved (fixed in 2.36.6-1)
bullseye: resolved (fixed in 2.36.6-1~deb11u1)
forky: resolved (fixed in 2.36.6-1)
sid: resolved (fixed in 2.36.6-1)
trixie: resolved (fixed in 2.36.6-1)
OSV
CVE-2022-32891: The issue was addressed with improved UI handling
osv·2023-02-27·CVSS 6.1
CVE-2022-32891 [MEDIUM] CVE-2022-32891: The issue was addressed with improved UI handling
The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchOS 9, iOS 16. Visiting a website that frames malicious content may lead to UI spoofing.
GHSA
GHSA-3r34-xx92-673h: The issue was addressed with improved UI handling
ghsa_unreviewed·2023-02-27
CVE-2022-32891 [MEDIUM] CWE-1021 GHSA-3r34-xx92-673h: The issue was addressed with improved UI handling
The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchOS 9, iOS 16. Visiting a website that frames malicious content may lead to UI spoofing.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://security.gentoo.org/glsa/202305-32https://support.apple.com/en-us/HT213442https://support.apple.com/en-us/HT213446https://support.apple.com/en-us/HT213486https://support.apple.com/en-us/HT213487https://security.gentoo.org/glsa/202305-32https://support.apple.com/en-us/HT213442https://support.apple.com/en-us/HT213446https://support.apple.com/en-us/HT213486https://support.apple.com/en-us/HT213487
2023-02-27
Published