CVE-2025-15032: Increased Spoofing risk; custom new window missing about:blank
Published Jan 16, 2026
·Updated
Missing about:blank indicator in custom-sized new windows in Dia before 1.9.0 on macOS could allow an attacker to spoof a trusted domain in the window title and mislead users about the current site.
Affected Software
1 affected component
Dia Dia<1.9.0
Remediation
Information
Upgrade Dia to a version 1.9.0 or later
Event History
Jan 16, 2026
CVE Published
via MITRE·06:11 PM
Data Sourced
via MITRE·06:11 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-15032?
CVE-2025-15032 has been identified as a medium severity vulnerability due to the potential for spoofing trusted domains.
2
How do I fix CVE-2025-15032?
To fix CVE-2025-15032, you should update Dia to version 1.9.0 or later.
3
What kind of attack does CVE-2025-15032 enable?
CVE-2025-15032 enables attackers to spoof a trusted domain in the window title, misleading users about the current site.
4
On which operating system is CVE-2025-15032 a concern?
CVE-2025-15032 specifically affects the Dia application running on macOS.
5
What versions of Dia are affected by CVE-2025-15032?
CVE-2025-15032 affects Dia versions prior to 1.9.0.