Missing about:blank indicator in custom-sized new windows in Dia before 1.9.0 on macOS could allow an attacker to spoof a trusted domain in the window title and mislead users about the current site.

Subscriptions

Vendors Products
The Browser Company Subscribe

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

Fixes

Solution

Upgrade Dia to a version 1.9.0 or later


Workaround

No workaround given by the vendor.

History

Mon, 19 Jan 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Dia
Dia dia
The Browser Company
The Browser Company dia
Vendors & Products Apple
Apple macos
Dia
Dia dia
The Browser Company
The Browser Company dia

Fri, 16 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 16 Jan 2026 18:30:00 +0000

Type Values Removed Values Added
Description Missing about:blank indicator in custom-sized new windows in Dia before 1.9.0 on macOS could allow an attacker to spoof a trusted domain in the window title and mislead users about the current site.
Title CVE-2025-15032: Increased Spoofing risk; custom new window missing about:blank
Weaknesses CWE-1021
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: BCNY

Published:

Updated: 2026-01-16T18:35:45.651Z

Reserved: 2025-12-22T15:25:37.344Z

Link: CVE-2025-15032

cve-icon Vulnrichment

Updated: 2026-01-16T18:35:36.532Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-16T19:16:16.220

Modified: 2026-01-26T15:05:57.190

Link: CVE-2025-15032

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-19T09:20:12Z

Weaknesses