CVE-2022-32891

Public on 2022-12-14
Modified on 2024-01-12
Description
The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchOS 9, iOS 16. Visiting a website that frames malicious content may lead to UI spoofing.
Severity
Medium severity
Medium
CVSS v3 Base Score
8.1
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2023 webkit2gtk3-2.36.1-1.amzn2022 Pending Fix
Amazon Linux 2 - Core webkitgtk3-2.4.11-2.amzn2.0.2 && webkitgtk4-2.28.2-3.amzn2.0.1 Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
NVD CVSSv3 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N