CVE-2025-15032 describes a user interface spoofing vulnerability in Dia before version 1.9.0 on macOS. This flaw allows an attacker to manipulate the window title of custom-sized new windows by omitting the "about:blank" indicator, potentially misleading users into believing they are interacting with a trusted domain. Rated with a CVSS score of 7.4 (HIGH), the vulnerability requires user interaction and could lead to high integrity impact, though it has low attack complexity and no confidentiality or availability impact. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| The Browser Company Of New York | Dia | >= 0, < 1.9.0CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.