CVE-2020-25779
Description
Trend Micro Antivirus for Mac 2020 (Consumer) has a vulnerability in which a Internationalized Domain Name homograph attack (Puny-code) could be used to add a malicious website to the approved websites list of Trend Micro Antivirus for Mac to bypass the web threat protection feature.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Internationalized Domain Name homograph attack bypasses web threat protection in Antivirus for Mac 2020.
Vulnerability
Trend Micro Antivirus for Mac 2020 (Consumer, version 10.x and below) fails to properly validate Internationalized Domain Names (IDNs) when processing the approved websites list. An attacker can craft a domain using Punycode homographs that visually resemble a legitimate domain, which the antivirus software then incorrectly treats as allowed, bypassing the web threat protection feature [1].
Exploitation
An attacker must first be able to convince the user to add a malicious website to the approved websites list via social engineering (e.g., phishing). The attacker then supplies a domain name containing IDN homoglyphs (Punycode) that visually mimics a trusted site. Once added to the list, the antivirus will not block connections to that domain, enabling the attack [1].
Impact
Successful exploitation allows the attacker to bypass Trend Micro's web threat protection for the disguised domain. The attacker gains a means to deliver malware or phishing content without the software's protection blocking the connection. No privilege escalation or system compromise occurs directly from this vulnerability [1].
Mitigation
Trend Micro released patches via ActiveUpdate for Antivirus for Mac 2020 (v10.5 build 1623 and v10.0 build 1803) and the new version 2021 (v11) resolves the issue. Customers on version 9.0 or below should upgrade to a supported version. Users running at least version 10.0 automatically receive the patch [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: 2020 (v10.x)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- helpcenter.trendmicro.com/en-us/article/TMKA-09949mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.