CVE-2022-22592
webkitgtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A logic issue was addressed with improved state management. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
Se abordó un problema de lógica con una administración de estados mejorada. Este problema es corregido en iOS versión 15.3 y iPadOS versión 15.3, watchOS versión 8.4, tvOS versión 15.3, Safari versión 15.3, macOS Monterey versión 12.2. El procesamiento de contenido web diseñado de forma maliciosa puede impedir que se aplique la Política de Seguridad de Contenidos
A vulnerability was found in WebKitGTK. The flaw exists due to a logic issue when processing HTML content in WebKit. This flaw allows a remote attacker to create a specially crafted web page, trick the victim into visiting it, and prevent the Content Security Policy from being enforced, allowing the remote attacker to bypass implemented security restrictions.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-01-05 CVE Reserved
- 2022-01-31 CVE Published
- 2024-08-03 CVE Updated
- 2024-10-22 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-1021: Improper Restriction of Rendered UI Layers or Frames
CAPEC
References (8)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://security.gentoo.org/glsa/202208-39 | 2022-09-09 | |
https://support.apple.com/en-us/HT213053 | 2022-09-09 | |
https://support.apple.com/en-us/HT213054 | 2022-09-09 | |
https://support.apple.com/en-us/HT213057 | 2022-09-09 | |
https://support.apple.com/en-us/HT213058 | 2022-09-09 | |
https://support.apple.com/en-us/HT213059 | 2022-09-09 | |
https://access.redhat.com/security/cve/CVE-2022-22592 | 2022-05-10 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2053185 | 2022-05-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | < 15.3 Search vendor "Apple" for product "Safari" and version " < 15.3" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Iphone Search vendor "Apple" for product "Iphone" | < 15.3 Search vendor "Apple" for product "Iphone" and version " < 15.3" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Ipados Search vendor "Apple" for product "Ipados" | < 15.3 Search vendor "Apple" for product "Ipados" and version " < 15.3" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Macos Search vendor "Apple" for product "Macos" | >= 12.0.0 < 12.2 Search vendor "Apple" for product "Macos" and version " >= 12.0.0 < 12.2" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Tvos Search vendor "Apple" for product "Tvos" | < 15.3 Search vendor "Apple" for product "Tvos" and version " < 15.3" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Watchos Search vendor "Apple" for product "Watchos" | < 8.4 Search vendor "Apple" for product "Watchos" and version " < 8.4" | - |
Affected
|