CVE-2022-42799
Publication date 1 November 2022
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
The issue was addressed with improved UI handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Visiting a malicious website may lead to user interface spoofing.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| qtwebkit-source | ||
| 22.04 LTS jammy | Not in release | |
| 20.04 LTS focal | Not in release | |
| 18.04 LTS bionic | Ignored | |
| 16.04 LTS xenial | Ignored | |
| 14.04 LTS trusty | Ignored end of standard support | |
| webkit2gtk | 24.04 LTS noble |
Fixed 2.38.2-1
|
| 22.04 LTS jammy |
Fixed 2.38.2-0ubuntu0.22.04.2
|
|
| 20.04 LTS focal |
Fixed 2.38.2-0ubuntu0.20.04.1
|
|
| 18.04 LTS bionic | Ignored | |
| 16.04 LTS xenial | Ignored | |
| 14.04 LTS trusty | Not in release | |
| webkitgtk | ||
| 22.04 LTS jammy | Not in release | |
| 20.04 LTS focal | Not in release | |
| 18.04 LTS bionic | Ignored | |
| 16.04 LTS xenial | Ignored | |
| 14.04 LTS trusty | Ignored end of standard support | |
| qtwebkit-opensource-src | 24.04 LTS noble | Ignored |
| 22.04 LTS jammy | Ignored | |
| 20.04 LTS focal | Ignored | |
| 18.04 LTS bionic | Ignored | |
| 16.04 LTS xenial | Ignored | |
| 14.04 LTS trusty | Ignored end of standard support | |
| wpewebkit | ||
| 22.04 LTS jammy | Ignored | |
| 20.04 LTS focal | Ignored | |
| 18.04 LTS bionic | Not in release | |
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | Ignored end of standard support |
Notes
jdstrand
webkit receives limited support. For details, see https://wiki.ubuntu.com/SecurityTeam/FAQ#webkit webkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score |
|
| Attack vector | Network |
| Attack complexity | Low |
| Privileges required | None |
| User interaction | Required |
| Scope | Changed |
| Confidentiality | Low |
| Integrity impact | Low |
| Availability impact | None |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
References
Related Ubuntu Security Notices (USN)
- USN-5730-1
- WebKitGTK vulnerabilities
- 17 November 2022
Other references
- https://support.apple.com/en-us/HT213488
- https://support.apple.com/en-us/HT213495
- https://support.apple.com/en-us/HT213492
- https://support.apple.com/en-us/HT213491
- https://support.apple.com/en-us/HT213489
- https://webkitgtk.org/security/WSA-2022-0010.html
- https://www.cve.org/CVERecord?id=CVE-2022-42799