CVE-2022-32919UI Misrepresentation / Clickjacking in Apple IOS AND Ipados

Severity
4.7MEDIUMNVD
EPSS
0.1%
top 78.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateJan 11

Description

The issue was addressed with improved UI handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Visiting a website that frames malicious content may lead to UI spoofing.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages9 packages

CVEListV5apple/macosunspecified13.1
NVDapple/macos< 13.1
NVDapple/ipados< 16.2
CVEListV5apple/ios_and_ipadosunspecified16.2

🔴Vulnerability Details

2
GHSA
GHSA-4m5w-jr92-m987: The issue was addressed with improved UI handling2024-01-11
OSV
CVE-2022-32919: The issue was addressed with improved UI handling2024-01-10

📋Vendor Advisories

4
Red Hat
webkitgtk: Visiting a website that frames malicious content may lead to UI spoofing.2023-11-15
Apple
CVE-2022-32919: iOS 16.2 and iPadOS 16.22022-12-13
Apple
CVE-2022-32919: macOS Ventura 13.12022-12-13
Debian
CVE-2022-32919: webkit2gtk - The issue was addressed with improved UI handling. This issue is fixed in iOS 16...2022