Description
The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, watchOS 11.4. Visiting a malicious website may lead to address bar spoofing.
Published: 2025-03-31
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Address Bar Spoofing
Action: Patch
AI Analysis

Impact

The vulnerability permits an adversary to manipulate a user’s browser so that the address bar displays a false URL when a malicious website is visited. This deception can facilitate phishing or other social‑engineering attacks without granting code execution, and it is classified as CWE‑451.

Affected Systems

Apple Safari, iOS, iPadOS, macOS and watchOS are affected. The issue is resolved in Safari 18.4, iOS 18.4, iPadOS 18.4, macOS Sequoia 15.4 and watchOS 11.4; earlier releases remain vulnerable.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate risk, while the EPSS score of less than 1 % suggests a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to lure users to a malicious site – a user‑initiated action – to trigger the spoofing; no remote code execution or privilege escalation results from a successful exploit.

Generated by OpenCVE AI on April 28, 2026 at 18:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Safari, iOS, iPadOS, macOS and watchOS to the latest versions (18.4, 18.4, 18.4, Sequoia 15.4 and 11.4 respectively) which incorporate the address‑bar validation fix.
  • Enable automatic software updates on all Apple devices so that future security patches are applied promptly.
  • Educate users to verify the true domain displayed in the address bar, check for HTTPS and other trust indicators, and refrain from interacting with suspicious or unfamiliar web sites.

Generated by OpenCVE AI on April 28, 2026 at 18:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8897 The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. Visiting a malicious website may lead to address bar spoofing.
History

Tue, 28 Apr 2026 19:15:00 +0000

Type Values Removed Values Added
Title Malicious Website Causes Address Bar Spoofing on Apple Browsers and Devices

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. Visiting a malicious website may lead to address bar spoofing. The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, watchOS 11.4. Visiting a malicious website may lead to address bar spoofing.
References

Mon, 03 Nov 2025 22:30:00 +0000


Mon, 03 Nov 2025 20:30:00 +0000

Type Values Removed Values Added
References

Fri, 04 Apr 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ipados
Apple iphone Os
Apple macos
Apple safari
CPEs cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple ipados
Apple iphone Os
Apple macos
Apple safari

Tue, 01 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 22:45:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. Visiting a malicious website may lead to address bar spoofing.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:22:47.921Z

Reserved: 2025-03-22T00:04:43.723Z

Link: CVE-2025-30467

cve-icon Vulnrichment

Updated: 2025-04-01T19:26:04.515Z

cve-icon NVD

Status : Modified

Published: 2025-03-31T23:15:27.967

Modified: 2026-04-02T19:19:42.047

Link: CVE-2025-30467

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T19:00:20Z

Weaknesses