Impact
The vulnerability is an improper restriction of rendered UI layers or frames in the Microsoft Bing Search app for iOS, which allows an unauthorized attacker to inject spoofed UI elements that appear legitimate. Based on the description, it is inferred that the attacker could manipulate the rendering of UI layers to deceive users. This flaw, classified as CWE‑1021, can be used to present deceptive content that misleads users into interacting with malicious interfaces, potentially leading to phishing or other social‑engineering attacks. The impact is primarily disclosure of sensitive information or unintended user actions driven by the fabricated UI.
Affected Systems
Affected vendors and products are Microsoft and the Microsoft Bing Search app for iOS. No specific version information is supplied, so the issue likely applies to all current releases of the app until a patch is issued.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in CISA's KEV catalog. Based on the description, the likely attack vector is inferred to be the delivery of spoofed UI content over a network path that the mobile device can reach, such as untrusted Wi‑Fi or cellular data. Once rendered, users may unknowingly expose sensitive information or cause unintended app behavior.
OpenCVE Enrichment