Impact
This vulnerability allows a malicious website to cause the browser to display a spoofed address bar, tricking users into believing they are viewing a legitimate site. The weakness stems from inadequate validation of the address bar rendering logic. While only moderate severity is assigned, an attacker could exploit it to initiate phishing attacks, potentially leading to credential theft or other social engineering exploits.
Affected Systems
Apple Safari on macOS, iOS, and iPadOS with versions before Safari 18.3, iOS 18.3, iPadOS 18.3, and macOS Sequoia 15.3. Devices running older releases are vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate impact. The EPSS score is less than 1 %, suggesting a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Attackers are likely to target users by enticing them to visit malicious sites that trigger the spoofing behavior.
OpenCVE Enrichment
EUVD