CVE-2022-32891

The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchOS 9, iOS 16. Visiting a website that frames malicious content may lead to UI spoofing.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:07

Type Values Removed Values Added
Summary
  • (es) El problema se solucionó mejorando el manejo de la interfaz de usuario. Este problema se solucionó en Safari 16, tvOS 16, watchOS 9, iOS 16. Visitar un sitio web que enmarque contenido malicioso puede provocar una suplantación de la interfaz de usuario.
References () https://security.gentoo.org/glsa/202305-32 - () https://security.gentoo.org/glsa/202305-32 -
References () https://support.apple.com/en-us/HT213442 - Vendor Advisory () https://support.apple.com/en-us/HT213442 - Vendor Advisory
References () https://support.apple.com/en-us/HT213446 - Vendor Advisory () https://support.apple.com/en-us/HT213446 - Vendor Advisory
References () https://support.apple.com/en-us/HT213486 - Vendor Advisory () https://support.apple.com/en-us/HT213486 - Vendor Advisory
References () https://support.apple.com/en-us/HT213487 - Vendor Advisory () https://support.apple.com/en-us/HT213487 - Vendor Advisory

30 May 2023, 06:15

Type Values Removed Values Added
References
  • (GENTOO) https://security.gentoo.org/glsa/202305-32 -

08 Mar 2023, 15:13

Type Values Removed Values Added
References (MISC) https://support.apple.com/en-us/HT213487 - (MISC) https://support.apple.com/en-us/HT213487 - Vendor Advisory
References (MISC) https://support.apple.com/en-us/HT213446 - (MISC) https://support.apple.com/en-us/HT213446 - Vendor Advisory
References (MISC) https://support.apple.com/en-us/HT213486 - (MISC) https://support.apple.com/en-us/HT213486 - Vendor Advisory
References (MISC) https://support.apple.com/en-us/HT213442 - (MISC) https://support.apple.com/en-us/HT213442 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CPE cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
CWE CWE-1021

27 Feb 2023, 20:25

Type Values Removed Values Added
New CVE

Information

Published : 2023-02-27 20:15

Updated : 2024-11-21 07:07


NVD link : CVE-2022-32891

Mitre link : CVE-2022-32891

CVE.ORG link : CVE-2022-32891


JSON object : View

Products Affected

apple

  • safari
  • iphone_os
  • watchos
  • tvos
CWE
CWE-1021

Improper Restriction of Rendered UI Layers or Frames