Impact
An input validation weakness in the mail processing subsystem was corrected in the latest releases. The flaw allows crafted email content to inject UI elements that cause the operating system to display a spoofed interface, potentially deceiving users about the origin of notifications or messages. This injection is a classic instance of web-based UI manipulation, identified as CWE-79.
Affected Systems
All devices running versions of Apple iOS prior to 18.5 and iPadOS prior to 18.5 (iPadOS 17.7.7 also receiving the fix). These include iPhone and iPad models that support the affected operating system releases.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate impact. The EPSS score of less than 1% shows that exploitation is expected to be very uncommon, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to craft an email that a user opens, making the vector indirect and dependent on social or phishing tactics. If successful, the attacker can manipulate the device’s user interface to mislead the user without achieving code execution.
OpenCVE Enrichment
EUVD