CVE-2022-46698
published 2022-12-15CVE-2022-46698: A logic issue was addressed with improved checks. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and…
PriorityP333medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.91%
55.8th percentile
A logic issue was addressed with improved checks. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may disclose sensitive user information.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | icloud | < 14.0 | 14.0 |
| apple | icloud_for_windows | — | — |
| apple | icloud_for_windows | >= unspecified < 14.1 | 14.1 |
| apple | ios_16.2_and_ipados | — | — |
| apple | ipados | < 16.2 | 16.2 |
| apple | iphone_os | < 16.2 | 16.2 |
| apple | macos | < 13.1 | 13.1 |
| apple | macos_ventura | — | — |
| apple | safari | < 16.2 | 16.2 |
| apple | safari | — | — |
| apple | tvos | < 16.2 | 16.2 |
| apple | tvos | >= unspecified < 16.2 | 16.2 |
| apple | tvos | >= unspecified < 13.1 | 13.1 |
| apple | tvos16.2 | — | — |
| apple | watchos | < 9.2 | 9.2 |
| apple | watchos | — | — |
| apple | watchos | >= unspecified < 9.2 | 9.2 |
| apple | watchos | >= unspecified < 16.2 | 16.2 |
| debian | webkit2gtk | < webkit2gtk 2.38.3-1 (bookworm) | webkit2gtk 2.38.3-1 (bookworm) |
| debian | wpewebkit | < webkit2gtk 2.38.3-1 (bookworm) | webkit2gtk 2.38.3-1 (bookworm) |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
WebKitGTK vulnerabilities
vendor_ubuntu·2023-01-09
CVE-2022-46699 WebKitGTK vulnerabilities
Title: WebKitGTK vulnerabilities
Summary: Several security issues were fixed in WebKitGTK.
Several security issues were discovered in the WebKitGTK Web and JavaScript
engines. If a user were tricked into viewing a malicious website, a remote
attacker could exploit a variety of issues related to web browser security,
including cross-site scripting attacks, denial of service attacks, and
arbitrary code execution.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use WebKitGTK, such as Epiphany, to make all the necessary changes.
Red Hat
webkitgtk: logic issue leading to user information disclosure
vendor_redhat·2022-12-15·CVSS 6.5
CVE-2022-46698 [MEDIUM] CWE-200 webkitgtk: logic issue leading to user information disclosure
webkitgtk: logic issue leading to user information disclosure
A logic issue was addressed with improved checks. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may disclose sensitive user information.
A logic issue was found in WebKitGTK and WPE WebKit. This flaw allows an attacker to process maliciously crafted web content that may disclose sensitive user information.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Out of support scope
Package: webkitgtk3 (Red Hat Enterprise Linux 7) - Out of support scope
Apple
CVE-2022-46698: macOS Ventura 13.1
vendor_apple·2022-12-13·CVSS 6.5
CVE-2022-46698 [MEDIUM] CVE-2022-46698: macOS Ventura 13.1
Apple Security Update: About the security content of macOS Ventura 13.1
Product: macOS Ventura
Version: 13.1
CVE: CVE-2022-46698
Component: WebKit
Impact: Processing maliciously crafted web content may disclose sensitive user information
Description: A logic issue was addressed with improved checks.
Apple
CVE-2022-46698: watchOS 9.2
vendor_apple·2022-12-13·CVSS 6.5
CVE-2022-46698 [MEDIUM] CVE-2022-46698: watchOS 9.2
Apple Security Update: About the security content of watchOS 9.2
Product: watchOS
Version: 9.2
CVE: CVE-2022-46698
Component: WebKit
Impact: Processing maliciously crafted web content may disclose sensitive user information
Description: A logic issue was addressed with improved checks.
Apple
CVE-2022-46698: iOS 16.2 and iPadOS 16.2
vendor_apple·2022-12-13·CVSS 6.5
CVE-2022-46698 [MEDIUM] CVE-2022-46698: iOS 16.2 and iPadOS 16.2
Apple Security Update: About the security content of iOS 16.2 and iPadOS 16.2
Product: iOS 16.2 and iPadOS
Version: 16.2
CVE: CVE-2022-46698
Component: WebKit
Impact: Processing maliciously crafted web content may disclose sensitive user information
Description: A logic issue was addressed with improved checks.
Apple
CVE-2022-46698: iCloud for Windows 14.1
vendor_apple·2022-12-13·CVSS 6.5
CVE-2022-46698 [MEDIUM] CVE-2022-46698: iCloud for Windows 14.1
Apple Security Update: About the security content of iCloud for Windows 14.1
Product: iCloud for Windows
Version: 14.1
CVE: CVE-2022-46698
Component: WebKit
Impact: Processing maliciously crafted web content may disclose sensitive user information
Description: A logic issue was addressed with improved checks.
Apple
CVE-2022-46698: tvOS16.2
vendor_apple·2022-12-13·CVSS 6.5
CVE-2022-46698 [MEDIUM] CVE-2022-46698: tvOS16.2
Apple Security Update: About the security content of tvOS16.2
Product: tvOS16.2
CVE: CVE-2022-46698
Component: WebKit
Impact: Processing maliciously crafted web content may disclose sensitive user information
Description: A logic issue was addressed with improved checks.
Apple
CVE-2022-46698: Safari 16.2
vendor_apple·2022-12-13·CVSS 6.5
CVE-2022-46698 [MEDIUM] CVE-2022-46698: Safari 16.2
Apple Security Update: About the security content of Safari 16.2
Product: Safari
Version: 16.2
CVE: CVE-2022-46698
Component: WebKit
Impact: Processing maliciously crafted web content may disclose sensitive user information
Description: A logic issue was addressed with improved checks.
Debian
CVE-2022-46698: webkit2gtk - A logic issue was addressed with improved checks. This issue is fixed in Safari ...
vendor_debian·2022·CVSS 6.5
CVE-2022-46698 [MEDIUM] CVE-2022-46698: webkit2gtk - A logic issue was addressed with improved checks. This issue is fixed in Safari ...
A logic issue was addressed with improved checks. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may disclose sensitive user information.
Scope: local
bookworm: resolved (fixed in 2.38.3-1)
bullseye: resolved (fixed in 2.38.3-1~deb11u1)
forky: resolved (fixed in 2.38.3-1)
sid: resolved (fixed in 2.38.3-1)
trixie: resolved (fixed in 2.38.3-1)
GHSA
GHSA-3mmq-4r29-8xqf: A logic issue was addressed with improved checks
ghsa_unreviewed·2022-12-15
CVE-2022-46698 [MEDIUM] CWE-693 GHSA-3mmq-4r29-8xqf: A logic issue was addressed with improved checks
A logic issue was addressed with improved checks. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may disclose sensitive user information.
OSV
CVE-2022-46698: A logic issue was addressed with improved checks
osv·2022-12-15·CVSS 6.5
CVE-2022-46698 [MEDIUM] CVE-2022-46698: A logic issue was addressed with improved checks
A logic issue was addressed with improved checks. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may disclose sensitive user information.
No detection rules found.
No public exploits indexed.
http://seclists.org/fulldisclosure/2022/Dec/20http://seclists.org/fulldisclosure/2022/Dec/23http://seclists.org/fulldisclosure/2022/Dec/26http://seclists.org/fulldisclosure/2022/Dec/27http://seclists.org/fulldisclosure/2022/Dec/28https://security.gentoo.org/glsa/202305-32https://support.apple.com/en-us/HT213530https://support.apple.com/en-us/HT213532https://support.apple.com/en-us/HT213535https://support.apple.com/en-us/HT213536https://support.apple.com/en-us/HT213537https://support.apple.com/en-us/HT213538http://seclists.org/fulldisclosure/2022/Dec/20http://seclists.org/fulldisclosure/2022/Dec/23http://seclists.org/fulldisclosure/2022/Dec/26http://seclists.org/fulldisclosure/2022/Dec/27http://seclists.org/fulldisclosure/2022/Dec/28https://security.gentoo.org/glsa/202305-32https://support.apple.com/en-us/HT213530https://support.apple.com/en-us/HT213532https://support.apple.com/en-us/HT213535https://support.apple.com/en-us/HT213536https://support.apple.com/en-us/HT213537https://support.apple.com/en-us/HT213538
2022-12-15
Published