Impact
The vulnerability permits an adversary to manipulate a user’s browser so that the address bar displays a false URL when a malicious website is visited. This deception can facilitate phishing or other social‑engineering attacks without granting code execution, and it is classified as CWE‑451.
Affected Systems
Apple Safari, iOS, iPadOS, macOS and watchOS are affected. The issue is resolved in Safari 18.4, iOS 18.4, iPadOS 18.4, macOS Sequoia 15.4 and watchOS 11.4; earlier releases remain vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate risk, while the EPSS score of less than 1 % suggests a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to lure users to a malicious site – a user‑initiated action – to trigger the spoofing; no remote code execution or privilege escalation results from a successful exploit.
OpenCVE Enrichment
EUVD