User Interface Spoofing in Apple's Products
CVE-2025-24113
4.3MEDIUM
Key Information:
- Vendor
- Apple
- Vendor
- CVE Published:
- 27 January 2025
Summary
A vulnerability in Apple's macOS, iOS, iPadOS, Safari, and visionOS products can lead to a spoofing attack where users may be misled by manipulated interfaces. This issue is mitigated in recent updates that enhance the user interface, and it emphasizes the importance of using the latest software versions to ensure protection against potential exploits that could arise from visiting malicious websites.
Affected Version(s)
iOS and iPadOS < 18.3
macOS < 15.3
Safari < 18.3
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved