CVE-2025-24113
35Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Attendcvss 4.3epss 0.8%
from disclosure to weapon
Published on NVDJan 27
VulnCheck+435d
exploitation probability
0.8%top 45% of all CVEs
observed exploitation
yesVulnCheck
The issue was addressed with improved UI. This issue is fixed in Safari 18.3, Safari 18.4, iOS 18.3 and iPadOS 18.3, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sequoia 15.4, visionOS 2.3, visionOS 2.4, watchOS 11.4. Visiting a malicious website may lead to user interface spoofing.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Affected products
Apple · iOS and iPadOSApple · iPadOSApple · macOSApple · SafariApple · visionOSApple · watchOSReferences
http://seclists.org/fulldisclosure/2025/Apr/12http://seclists.org/fulldisclosure/2025/Apr/13http://seclists.org/fulldisclosure/2025/Apr/2http://seclists.org/fulldisclosure/2025/Apr/4http://seclists.org/fulldisclosure/2025/Apr/5http://seclists.org/fulldisclosure/2025/Apr/8http://seclists.org/fulldisclosure/2025/Jan/12http://seclists.org/fulldisclosure/2025/Jan/13http://seclists.org/fulldisclosure/2025/Jan/15http://seclists.org/fulldisclosure/2025/Jan/20https://support.apple.com/en-us/122066https://support.apple.com/en-us/122068