VulnerabilityModified
CVE-2022-32891
Visiting a website that frames malicious content may lead to UI spoofing.
MEDIUM 6.1EPSS 0.71%
Does this matter?
Lower severity and a low EPSS score (0.71%). Track it; it rarely justifies an emergency change on its own.
Description
The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchOS 9, iOS 16. Visiting a website that frames malicious content may lead to UI spoofing.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.71% probability · 52th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1021
- Affected
- apple/safari · apple/iphone os · apple/tvos · apple/watchos
- Source
- product-security@apple.com
References
- https://security.gentoo.org/glsa/202305-32
- https://support.apple.com/en-us/HT213442Vendor Advisory
- https://support.apple.com/en-us/HT213446Vendor Advisory
- https://support.apple.com/en-us/HT213486Vendor Advisory
- https://support.apple.com/en-us/HT213487Vendor Advisory
- https://security.gentoo.org/glsa/202305-32
- https://support.apple.com/en-us/HT213442Vendor Advisory
- https://support.apple.com/en-us/HT213446Vendor Advisory
- https://support.apple.com/en-us/HT213486Vendor Advisory
- https://support.apple.com/en-us/HT213487Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.