HTTP: Apple Safari IDN Punycode Canadian Syllabics URL Spoofing

This signature detects attempts to exploit a known vulnerability against Apple Safari IDN. A successful attack can lead to security bypass.

Extended Description

The issue was addressed with improved UI handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. Visiting a website that frames malicious content may lead to UI spoofing.

Affected Products

Apple ipados

Short Name
HTTP:STC:APPLE-URL-SPOOF
Severity
Minor
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
Apple CVE-2022-32816 Canadian IDN Punycode Safari Spoofing Syllabics URL
Release Date
11/29/2022
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3590
False Positive
Rarely
Vendors

Apple

Found a potential security threat?