Description
The issue was addressed by adding additional logic. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. Visiting a malicious website may lead to address bar spoofing.
Published: 2025-01-27
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Address Bar Spoofing
Action: Apply Update
AI Analysis

Impact

This vulnerability allows a malicious website to cause the browser to display a spoofed address bar, tricking users into believing they are viewing a legitimate site. The weakness stems from inadequate validation of the address bar rendering logic. While only moderate severity is assigned, an attacker could exploit it to initiate phishing attacks, potentially leading to credential theft or other social engineering exploits.

Affected Systems

Apple Safari on macOS, iOS, and iPadOS with versions before Safari 18.3, iOS 18.3, iPadOS 18.3, and macOS Sequoia 15.3. Devices running older releases are vulnerable.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate impact. The EPSS score is less than 1 %, suggesting a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Attackers are likely to target users by enticing them to visit malicious sites that trigger the spoofing behavior.

Generated by OpenCVE AI on April 28, 2026 at 04:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Safari 18.3 or later on macOS and iOS devices.
  • Update iOS to version 18.3 and iPadOS to version 18.3.
  • Upgrade macOS to Sequoia 15.3 or a later release.

Generated by OpenCVE AI on April 28, 2026 at 04:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3638 The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3. Visiting a malicious website may lead to address bar spoofing.
History

Tue, 28 Apr 2026 04:30:00 +0000

Type Values Removed Values Added
Title Address Bar Spoofing Vulnerability in Apple Safari, iOS, iPadOS, and macOS
Weaknesses CWE-601
CWE-614

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3. Visiting a malicious website may lead to address bar spoofing. The issue was addressed by adding additional logic. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. Visiting a malicious website may lead to address bar spoofing.

Mon, 03 Nov 2025 21:30:00 +0000


Fri, 31 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jan 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ipados
Apple iphone Os
Apple macos
Apple safari
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple ipados
Apple iphone Os
Apple macos
Apple safari
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Mon, 27 Jan 2025 22:00:00 +0000

Type Values Removed Values Added
Description The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3. Visiting a malicious website may lead to address bar spoofing.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:10:01.292Z

Reserved: 2025-01-17T00:00:44.973Z

Link: CVE-2025-24128

cve-icon Vulnrichment

Updated: 2025-11-03T21:03:00.599Z

cve-icon NVD

Status : Modified

Published: 2025-01-27T22:15:17.793

Modified: 2026-04-02T19:19:04.233

Link: CVE-2025-24128

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T04:15:16Z