Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2025-24113

CVE-2025-24113: Apple Safari XSS Vulnerability

CVE-2025-24113 is a cross-site scripting flaw in Apple Safari that enables UI spoofing attacks through malicious websites. This article covers the technical details, affected versions, security impact, and mitigation.

Updated:

CVE-2025-24113 Overview

CVE-2025-24113 is a user interface spoofing vulnerability affecting Apple Safari and multiple Apple operating systems. The flaw allows a malicious website to manipulate the browser UI in ways that mislead users about the content or origin of what they are viewing. Apple addressed the issue with improved UI handling. Successful exploitation requires the victim to visit attacker-controlled content, making phishing and social engineering the primary delivery mechanisms. The vulnerability is classified under [CWE-NVD-noinfo] as no specific weakness category was assigned by NVD.

Critical Impact

Visiting a malicious website may lead to user interface spoofing, enabling phishing and credential theft scenarios against users of unpatched Apple devices.

Affected Products

  • Apple Safari (prior to 18.3 and 18.4)
  • Apple iOS and iPadOS (prior to 17.7.6, 18.3, and 18.4)
  • Apple macOS Sequoia (prior to 15.3 and 15.4), visionOS (prior to 2.3 and 2.4), watchOS (prior to 11.4)

Discovery Timeline

  • 2025-01-27 - CVE-2025-24113 published to NVD
  • 2026-04-02 - Last updated in NVD database

Technical Details for CVE-2025-24113

Vulnerability Analysis

The vulnerability resides in how Safari and related Apple platforms render user interface elements when processing content from a malicious website. An attacker who controls a webpage can craft content that manipulates the browser chrome or UI overlay to misrepresent the origin or trustworthiness of displayed information. This class of flaw enables address bar spoofing, security indicator manipulation, or overlay attacks that deceive users into trusting malicious content. The vulnerability requires user interaction, since the victim must navigate to attacker-controlled content for exploitation. The attack does not compromise confidentiality or availability, but it does affect integrity by allowing the attacker to mislead the user. Apple resolved the issue with improved UI rendering across Safari 18.3, Safari 18.4, iOS and iPadOS 18.3 and 18.4, iPadOS 17.7.6, macOS Sequoia 15.3 and 15.4, visionOS 2.3 and 2.4, and watchOS 11.4.

Root Cause

The root cause is improper handling of UI rendering logic when a webpage triggers specific conditions that allow visual elements to overlap, obscure, or impersonate trusted browser indicators. Apple's advisory states the fix was implemented through improved UI handling, indicating the underlying defect was in how the renderer composed or displayed interface components alongside untrusted web content.

Attack Vector

Exploitation begins when a user visits a malicious or compromised website over the network. The attacker delivers crafted HTML, CSS, or JavaScript content that triggers the UI spoofing condition. Once rendered, the spoofed UI can deceive the user into entering credentials, approving prompts, or trusting fraudulent content. The attack vector is purely web-based and requires no elevated privileges on the target device, but it does require active user interaction with the malicious page.

Detection Methods for CVE-2025-24113

Indicators of Compromise

  • Outbound connections from Apple devices to recently registered or low-reputation domains hosting credential-harvesting pages.
  • Browser telemetry showing repeated visits to URLs with unusual subdomain patterns that mimic trusted brands.
  • Endpoint logs indicating Safari versions earlier than 18.3 on macOS, iOS, or iPadOS deployments.

Detection Strategies

  • Inventory all Apple endpoints and identify devices running Safari or operating system versions below the patched releases listed in Apple support documents.
  • Monitor web proxy and DNS logs for connections to phishing infrastructure leveraging UI spoofing techniques.
  • Correlate phishing report submissions from users with the browser version of the reporting device to identify exposure.

Monitoring Recommendations

  • Enable URL reputation filtering at the network egress to block known phishing domains before they reach unpatched Safari clients.
  • Track patch compliance metrics for iOS, iPadOS, macOS, visionOS, and watchOS through mobile device management (MDM) reporting.
  • Alert on Safari user-agent strings reflecting vulnerable versions during authentication events to identify high-risk sessions.

How to Mitigate CVE-2025-24113

Immediate Actions Required

  • Update Safari to version 18.3 or 18.4, and update iOS and iPadOS to 17.7.6, 18.3, or 18.4 as appropriate for the device.
  • Update macOS Sequoia to 15.3 or 15.4, visionOS to 2.3 or 2.4, and watchOS to 11.4 across all managed Apple devices.
  • Reinforce user awareness training focused on inspecting URLs and security indicators before submitting credentials.

Patch Information

Apple released patches across multiple platforms. Refer to Apple Support Document 122066, Apple Support Document 122068, Apple Support Document 122073, and Apple Support Document 122074 for the corresponding security content and version mappings.

Workarounds

  • Restrict browsing on unpatched devices to a vetted allowlist of trusted domains through MDM web content filtering.
  • Deploy enterprise phishing protection at the email and DNS layers to reduce the likelihood of users reaching malicious sites.
  • Enforce multi-factor authentication on all sensitive applications so that credentials harvested via spoofed UI cannot be used in isolation.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.