Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-32919
HistoryJan 10, 2024 - 12:00 a.m.

CVE-2022-32919

2024-01-1000:00:00
ubuntu.com
ubuntu.com
21
ui handling
ios 16.2
ipados 16.2
macos ventura 13.1
malicious content
website
ui spoofing
webkit
ubuntu
jsc engine

4.7 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

4.7 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.1%

The issue was addressed with improved UI handling. This issue is fixed in
iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Visiting a website that
frames malicious content may lead to UI spoofing.

Notes

Author Note
jdstrand webkit receives limited support. For details, see https://wiki.ubuntu.com/SecurityTeam/FAQ#webkit webkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8
mdeslaur It is no longer possible to build new webkit2gtk versions on focal and earlier. Marking as ignored.
OSVersionArchitecturePackageVersionFilename
ubuntu20.04noarchwebkit2gtk< 2.38.4-0ubuntu0.20.04.2UNKNOWN
ubuntu22.04noarchwebkit2gtk< 2.38.4-0ubuntu0.22.04.1UNKNOWN
ubuntu23.04noarchwebkit2gtk< 2.38.4-2UNKNOWN
ubuntu23.10noarchwebkit2gtk< 2.38.4-2UNKNOWN
ubuntu24.04noarchwebkit2gtk< 2.38.4-2UNKNOWN

4.7 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

4.7 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.1%