CVE-2025-24128

The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3. Visiting a malicious website may lead to address bar spoofing.
References
Link Resource
https://support.apple.com/en-us/122066 Release Notes Vendor Advisory
https://support.apple.com/en-us/122068 Release Notes Vendor Advisory
https://support.apple.com/en-us/122074 Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

History

31 Jan 2025, 14:41

Type Values Removed Values Added
Summary
  • (es) El problema se solucionó agregando lógica adicional. Este problema se solucionó en macOS Sequoia 15.3, Safari 18.3, iOS 18.3 y iPadOS 18.3. Visitar un sitio web malicioso puede provocar la suplantación de la barra de direcciones.
First Time Apple
Apple ipados
Apple macos
Apple safari
Apple iphone Os
References () https://support.apple.com/en-us/122066 - () https://support.apple.com/en-us/122066 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122068 - () https://support.apple.com/en-us/122068 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122074 - () https://support.apple.com/en-us/122074 - Release Notes, Vendor Advisory
CPE cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3

27 Jan 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-27 22:15

Updated : 2025-01-31 22:15


NVD link : CVE-2025-24128

Mitre link : CVE-2025-24128

CVE.ORG link : CVE-2025-24128


JSON object : View

Products Affected

apple

  • iphone_os
  • ipados
  • macos
  • safari