{ "data_type": "CVE", "data_format": "MITRE", "data_version": "4.0", "CVE_data_meta": { "ID": "CVE-2022-42799", "ASSIGNER": "product-security@apple.com", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "vendor_name": "Apple", "product": { "product_data": [ { "product_name": "macOS", "version": { "version_data": [ { "version_affected": "<", "version_value": "13" } ] } }, { "product_name": "tvOS", "version": { "version_data": [ { "version_affected": "<", "version_value": "16.1" } ] } }, { "product_name": "tvOS", "version": { "version_data": [ { "version_affected": "<", "version_value": "16.1" } ] } }, { "product_name": "tvOS", "version": { "version_data": [ { "version_affected": "<", "version_value": "16.1" } ] } }, { "product_name": "watchOS", "version": { "version_data": [ { "version_affected": "<", "version_value": "9.1" } ] } } ] } } ] } }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Visiting a malicious website may lead to user interface spoofing" } ] } ] }, "references": { "reference_data": [ { "refsource": "MISC", "url": "https://support.apple.com/en-us/HT213488", "name": "https://support.apple.com/en-us/HT213488" }, { "refsource": "MISC", "url": "https://support.apple.com/en-us/HT213489", "name": "https://support.apple.com/en-us/HT213489" }, { "refsource": "MISC", "url": "https://support.apple.com/en-us/HT213492", "name": "https://support.apple.com/en-us/HT213492" }, { "refsource": "MISC", "url": "https://support.apple.com/en-us/HT213495", "name": "https://support.apple.com/en-us/HT213495" }, { "refsource": "MISC", "url": "https://support.apple.com/en-us/HT213491", "name": "https://support.apple.com/en-us/HT213491" }, { "refsource": "MLIST", "name": "[oss-security] 20221104 WebKitGTK and WPE WebKit Security Advisory WSA-2022-0010", "url": "http://www.openwall.com/lists/oss-security/2022/11/04/4" }, { "refsource": "FEDORA", "name": "FEDORA-2022-08fdc4138a", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5LF4LYP725XZ7RWOPFUV6DGPN4Q5DUU4/" }, { "refsource": "DEBIAN", "name": "DSA-5273", "url": "https://www.debian.org/security/2022/dsa-5273" }, { "refsource": "DEBIAN", "name": "DSA-5274", "url": "https://www.debian.org/security/2022/dsa-5274" }, { "refsource": "MLIST", "name": "[debian-lts-announce] 20221109 [SECURITY] [DLA 3183-1] webkit2gtk security update", "url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00010.html" }, { "refsource": "FEDORA", "name": "FEDORA-2022-ce32af66d6", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AQKLEGJK3LHAKUQOLBHNR2DI3IUGLLTY/" }, { "refsource": "FEDORA", "name": "FEDORA-2022-e7726761c4", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JOFKX6BUEJFECSVFV6P5INQCOYQBB4NZ/" }, { "refsource": "GENTOO", "name": "GLSA-202305-32", "url": "https://security.gentoo.org/glsa/202305-32" } ] }, "description": { "description_data": [ { "lang": "eng", "value": "The issue was addressed with improved UI handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Visiting a malicious website may lead to user interface spoofing." } ] } }