User Interface Spoofing in Apple's Products
CVE-2025-24113

4.3MEDIUM

Key Information:

Vendor
Apple
Vendor
CVE Published:
27 January 2025

Summary

A vulnerability in Apple's macOS, iOS, iPadOS, Safari, and visionOS products can lead to a spoofing attack where users may be misled by manipulated interfaces. This issue is mitigated in recent updates that enhance the user interface, and it emphasizes the importance of using the latest software versions to ensure protection against potential exploits that could arise from visiting malicious websites.

Affected Version(s)

iOS and iPadOS < 18.3

macOS < 15.3

Safari < 18.3

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.