CVE-2025-24128

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 27, 2025
Updated: Jan 31, 2025

Summary

CVE-2025-24128 is a vulnerability affecting macOS, iOS, and iPadOS that allows for address bar spoofing. Malicious websites can exploit this issue, potentially tricking users into entering sensitive information. Apple addressed this vulnerability by adding additional logic in macOS Sequoia 15.3, Safari 18.3, iOS 18.3, and iPadOS 18.3. Users are advised to update their systems to mitigate the risk. This issue may pose a significant security concern for those who frequently visit untrusted websites.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share