Apple WebKit and Safari Address Bar Spoofing Vulnerability

Vulnerability

A vulnerability in WebKit, the engine that powers Safari, has been identified, which can lead to address bar spoofing. This issue is present in Safari 18.2 and earlier versions, as well as in macOS Ventura, macOS Sonoma, and iOS 18.2 and earlier. The vulnerability arises when a user visits a malicious website, potentially misleading them about the authenticity or security of the site.

Impact

Exploitation of this vulnerability can cause address bar spoofing, where the displayed URL does not accurately represent the site being visited, potentially leading to phishing or other security risks.

Remediation

Users can update to macOS Sequoia 15.3, Safari 18.3, iOS 18.3, or iPadOS 18.3 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
4.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.