Missing about:blank indicator in custom-sized new windows in Dia before 1.9.0 on macOS could allow an attacker to spoof a trusted domain in the window title and mislead users about the current site.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-01-16 19:16
Updated : 2026-01-26 15:05
NVD link : CVE-2025-15032
Mitre link : CVE-2025-15032
CVE.ORG link : CVE-2025-15032
JSON object : View
Products Affected
No product.
CWE
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
