CVE-2022-32891UI Misrepresentation / Clickjacking in Apple Safari

Severity
6.1MEDIUMNVD
EPSS
0.1%
top 74.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 27

Description

The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchOS 9, iOS 16. Visiting a website that frames malicious content may lead to UI spoofing.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages7 packages

NVDapple/tvos< 16.0
CVEListV5apple/safariunspecified16
NVDapple/safari< 16.0
CVEListV5apple/watchosunspecified9+1
NVDapple/watchos< 9.0

🔴Vulnerability Details

3
CVEList
CVE-2022-32891: The issue was addressed with improved UI handling2023-02-27
OSV
CVE-2022-32891: The issue was addressed with improved UI handling2023-02-27
GHSA
GHSA-3r34-xx92-673h: The issue was addressed with improved UI handling2023-02-27

📋Vendor Advisories

6
Red Hat
webkitgtk: UI spoofing while Visiting a website that frames malicious content2022-09-12
Apple
CVE-2022-32891: tvOS 162022-09-12
Apple
CVE-2022-32891: watchOS 92022-09-12
Apple
CVE-2022-32891: iOS 162022-09-12
Apple
CVE-2022-32891: Safari 162022-09-12
CVE-2022-32891 — UI Misrepresentation / Clickjacking | cvebase