CVE-2025-24113
published 2025-01-27CVE-2025-24113: The issue was addressed with improved UI. This issue is fixed in Safari 18.3, Safari 18.4, iOS 18.3 and iPadOS 18.3, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6…
PriorityP179medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
ITWVulnCheck KEV
Exploited in the wild
EPSS
0.78%
51.8th percentile
The issue was addressed with improved UI. This issue is fixed in Safari 18.3, Safari 18.4, iOS 18.3 and iPadOS 18.3, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sequoia 15.4, visionOS 2.3, visionOS 2.4, watchOS 11.4. Visiting a malicious website may lead to user interface spoofing.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_18.3_and_ipados | — | — |
| apple | ios_18.4_and_ipados | — | — |
| apple | ios_and_ipados | < 18.3 | 18.3 |
| apple | ios_and_ipados | < 18.4 | 18.4 |
| apple | ipados | < 17.7.6 | 17.7.6 |
| apple | ipados | < 18.3 | 18.3 |
| apple | ipados | — | — |
| apple | iphone_os | < 18.3 | 18.3 |
| apple | macos | < 15.4 | 15.4 |
| apple | macos | < 15.3 | 15.3 |
| apple | macos_sequoia | — | — |
| apple | macos_sequoia | — | — |
| apple | safari | < 18.4 | 18.4 |
| apple | safari | < 18.3 | 18.3 |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | visionos | < 2.4 | 2.4 |
| apple | visionos | < 2.3 | 2.3 |
| apple | visionos | — | — |
| apple | visionos | — | — |
| apple | watchos | < 11.4 | 11.4 |
| apple | watchos | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2025-24113 is a UI spoofing vulnerability in Safari triggered by visiting a malicious website; detection should focus on monitoring for suspicious Safari browser UI manipulation or address bar spoofing behaviors originating from untrusted web content. ↗
- ·The fix was delivered via a UI improvement across multiple Apple platforms; patched versions are Safari 18.3/18.4, iOS/iPadOS 18.3/18.4, iPadOS 17.7.6, macOS Sequoia 15.3/15.4, visionOS 2.3/2.4, and watchOS 11.4. No technical exploitation details or IOCs are publicly disclosed in available sources. ↗
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
vulncheck4.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2025-24113: watchOS 11.4
vendor_apple·2025-04-01·CVSS 4.3
CVE-2025-24113 [MEDIUM] CVE-2025-24113: watchOS 11.4
Apple Security Update: About the security content of watchOS 11.4
Product: watchOS
Version: 11.4
CVE: CVE-2025-24113
Component: Safari
Impact: Visiting a malicious website may lead to user interface spoofing
Description: The issue was addressed with improved UI.
Apple
CVE-2025-24113: macOS Sequoia 15.4
vendor_apple·2025-03-31·CVSS 4.3
CVE-2025-24113 [MEDIUM] CVE-2025-24113: macOS Sequoia 15.4
Apple Security Update: About the security content of macOS Sequoia 15.4
Product: macOS Sequoia
Version: 15.4
CVE: CVE-2025-24113
Component: Safari
Impact: Visiting a malicious website may lead to user interface spoofing
Description: The issue was addressed with improved UI.
Apple
CVE-2025-24113: iOS 18.4 and iPadOS 18.4
vendor_apple·2025-03-31·CVSS 4.3
CVE-2025-24113 [MEDIUM] CVE-2025-24113: iOS 18.4 and iPadOS 18.4
Apple Security Update: About the security content of iOS 18.4 and iPadOS 18.4
Product: iOS 18.4 and iPadOS
Version: 18.4
CVE: CVE-2025-24113
Component: Safari
Impact: Visiting a malicious website may lead to user interface spoofing
Description: The issue was addressed with improved UI.
Apple
CVE-2025-24113: Safari 18.4
vendor_apple·2025-03-31·CVSS 4.3
CVE-2025-24113 [MEDIUM] CVE-2025-24113: Safari 18.4
Apple Security Update: About the security content of Safari 18.4
Product: Safari
Version: 18.4
CVE: CVE-2025-24113
Component: Safari
Impact: Visiting a malicious website may lead to user interface spoofing
Description: The issue was addressed with improved UI.
Apple
CVE-2025-24113: iPadOS 17.7.6
vendor_apple·2025-03-31·CVSS 4.3
CVE-2025-24113 [MEDIUM] CVE-2025-24113: iPadOS 17.7.6
Apple Security Update: About the security content of iPadOS 17.7.6
Product: iPadOS
Version: 17.7.6
CVE: CVE-2025-24113
Component: Safari
Impact: Visiting a malicious website may lead to user interface spoofing
Description: The issue was addressed with improved UI.
Apple
CVE-2025-24113: visionOS 2.4
vendor_apple·2025-03-31·CVSS 4.3
CVE-2025-24113 [MEDIUM] CVE-2025-24113: visionOS 2.4
Apple Security Update: About the security content of visionOS 2.4
Product: visionOS
Version: 2.4
CVE: CVE-2025-24113
Component: Safari
Impact: Visiting a malicious website may lead to user interface spoofing
Description: The issue was addressed with improved UI.
Apple
CVE-2025-24113: Safari 18.3
vendor_apple·2025-01-27·CVSS 4.3
CVE-2025-24113 [MEDIUM] CVE-2025-24113: Safari 18.3
Apple Security Update: About the security content of Safari 18.3
Product: Safari
Version: 18.3
CVE: CVE-2025-24113
Component: Safari
Impact: Visiting a malicious website may lead to user interface spoofing
Description: The issue was addressed with improved UI.
Apple
CVE-2025-24113: visionOS 2.3
vendor_apple·2025-01-27·CVSS 4.3
CVE-2025-24113 [MEDIUM] CVE-2025-24113: visionOS 2.3
Apple Security Update: About the security content of visionOS 2.3
Product: visionOS
Version: 2.3
CVE: CVE-2025-24113
Component: Safari
Impact: Visiting a malicious website may lead to user interface spoofing
Description: The issue was addressed with improved UI.
Apple
CVE-2025-24113: iOS 18.3 and iPadOS 18.3
vendor_apple·2025-01-27·CVSS 4.3
CVE-2025-24113 [MEDIUM] CVE-2025-24113: iOS 18.3 and iPadOS 18.3
Apple Security Update: About the security content of iOS 18.3 and iPadOS 18.3
Product: iOS 18.3 and iPadOS
Version: 18.3
CVE: CVE-2025-24113
Component: Safari
Impact: Visiting a malicious website may lead to user interface spoofing
Description: The issue was addressed with improved UI.
Apple
CVE-2025-24113: macOS Sequoia 15.3
vendor_apple·2025-01-27·CVSS 4.3
CVE-2025-24113 [MEDIUM] CVE-2025-24113: macOS Sequoia 15.3
Apple Security Update: About the security content of macOS Sequoia 15.3
Product: macOS Sequoia
Version: 15.3
CVE: CVE-2025-24113
Component: Safari
Impact: Visiting a malicious website may lead to user interface spoofing
Description: The issue was addressed with improved UI.
GHSA
GHSA-463x-cx2r-cx32: The issue was addressed with improved UI
ghsa_unreviewed·2025-01-28
CVE-2025-24113 [MEDIUM] GHSA-463x-cx2r-cx32: The issue was addressed with improved UI
The issue was addressed with improved UI. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, visionOS 2.3. Visiting a malicious website may lead to user interface spoofing.
VulnCheck
Apple Safari/iOS/iPadOS/visionOS/watchOS and macOS Sequoia Interface Spoofing Vulnerability
vulncheck·2025·CVSS 4.3
CVE-2025-24113 [MEDIUM] Apple Safari/iOS/iPadOS/visionOS/watchOS and macOS Sequoia Interface Spoofing Vulnerability
Apple Safari/iOS/iPadOS/visionOS/watchOS and macOS Sequoia Interface Spoofing Vulnerability
The issue was addressed with improved UI. This issue is fixed in Safari 18.3, Safari 18.4, iOS 18.3 and iPadOS 18.3, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sequoia 15.4, visionOS 2.3, visionOS 2.4, watchOS 11.4. Visiting a malicious website may lead to user interface spoofing.
Affected: Apple safari
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://media.jamf.com/documents/white-papers/security-360-mac-2026.pdf
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://support.apple.com/en-us/122066https://support.apple.com/en-us/122068https://support.apple.com/en-us/122073https://support.apple.com/en-us/122074https://support.apple.com/en-us/122371https://support.apple.com/en-us/122372https://support.apple.com/en-us/122373https://support.apple.com/en-us/122376https://support.apple.com/en-us/122378https://support.apple.com/en-us/122379http://seclists.org/fulldisclosure/2025/Apr/12http://seclists.org/fulldisclosure/2025/Apr/13http://seclists.org/fulldisclosure/2025/Apr/2http://seclists.org/fulldisclosure/2025/Apr/4http://seclists.org/fulldisclosure/2025/Apr/5http://seclists.org/fulldisclosure/2025/Apr/8http://seclists.org/fulldisclosure/2025/Jan/12http://seclists.org/fulldisclosure/2025/Jan/13http://seclists.org/fulldisclosure/2025/Jan/15http://seclists.org/fulldisclosure/2025/Jan/20
2025-01-27
Published
Exploited in the wild