CVE-2025-24113
Description
The issue was addressed with improved UI. This issue is fixed in Safari 18.3, Safari 18.4, iOS 18.3 and iPadOS 18.3, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sequoia 15.4, visionOS 2.3, visionOS 2.4, watchOS 11.4. Visiting a malicious website may lead to user interface spoofing.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Visiting a malicious website may allow user interface spoofing due to an insufficiently robust UI in Apple Safari, iOS, iPadOS, macOS, visionOS, and watchOS.
Vulnerability
Overview
CVE-2025-24113 is a user interface spoofing vulnerability in Apple WebKit, affecting Safari, iOS, iPadOS, macOS, visionOS, and watchOS. The root cause is an insufficiently robust user interface that could be manipulated by a malicious website to present misleading appearance to the user.[1][2]
Exploitation
Scenario
The attack vector is network-based, requiring the victim to visit a specially crafted malicious website. No authentication is needed; the exploitation occurs purely through browsing.[1] The issue was addressed by improving the UI logic to better resist spoofing attempts.[1][2][3]
Impact
If successfully exploited, an attacker could perform user interface spoofing, potentially tricking the user into trusting a fake dialog or webpage, leading to disclosure of sensitive information or unintended actions.[1]
Mitigation
Apple has released patches in Safari 18.3, Safari 18.4, iOS 18.3/iPadOS 18.3, iOS 18.4/iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sequoia 15.4, visionOS 2.3, visionOS 2.4, and watchOS 11.4.[1][2][3][4] There is no known workaround; users are advised to update to the latest software versions.
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
8cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*range: <18.3
- (no CPE)range: <18.3
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*range: <15.3
- (no CPE)range: <15.3
- Range: <18.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
20- support.apple.com/en-us/122066nvdRelease NotesVendor Advisory
- support.apple.com/en-us/122068nvdRelease NotesVendor Advisory
- support.apple.com/en-us/122073nvdRelease NotesVendor Advisory
- support.apple.com/en-us/122074nvdRelease NotesVendor Advisory
- seclists.org/fulldisclosure/2025/Apr/12nvd
- seclists.org/fulldisclosure/2025/Apr/13nvd
- seclists.org/fulldisclosure/2025/Apr/2nvd
- seclists.org/fulldisclosure/2025/Apr/4nvd
- seclists.org/fulldisclosure/2025/Apr/5nvd
- seclists.org/fulldisclosure/2025/Apr/8nvd
- seclists.org/fulldisclosure/2025/Jan/12nvd
- seclists.org/fulldisclosure/2025/Jan/13nvd
- seclists.org/fulldisclosure/2025/Jan/15nvd
- seclists.org/fulldisclosure/2025/Jan/20nvd
- support.apple.com/en-us/122371nvd
- support.apple.com/en-us/122372nvd
- support.apple.com/en-us/122373nvd
- support.apple.com/en-us/122376nvd
- support.apple.com/en-us/122378nvd
- support.apple.com/en-us/122379nvd
News mentions
0No linked articles in our index yet.