← Back

CVE-2025-24225

nvd nist
Published: May 12, 2025Modified: Apr 2, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

An injection issue was addressed with improved input validation. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. Processing an email may lead to user interface spoofing.

Affected (3)

Products: Apple: Ipados, Iphone Os
2 products
Ipados
Iphone Os
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Before 17.7.7
From 18.0 to 18.5
Before 18.5

References (3)

Source: product-security@apple.com
Release NotesVendor Advisory
Source: product-security@apple.com
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.