Cyber Posture

CVE-2025-25333

High

Published: 27 February 2025

Published
27 February 2025
Modified
15 April 2026
KEV Added
Patch
CVSS Score 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.0022 44.0th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Description

An adversary may rely upon a user clicking a malicious link in order to gain execution.

Security Summary

CVE-2025-25333 is a vulnerability in the IKEA CN iOS app version 4.13.0 that enables attackers to access sensitive user information through a crafted link. Published on 2025-02-27, it carries a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), highlighting high confidentiality impact with network accessibility, low complexity, no privileges or user interaction required, and no effect on integrity or availability. The issue aligns with CWE-200, improper handling of sensitive information exposure.

The attack scenario involves unauthenticated remote attackers crafting and distributing malicious links to targeted users of the vulnerable app. Upon interaction with the link, attackers can retrieve sensitive user data without further authentication, making it exploitable by anyone with basic network reach to potential victims running IKEA CN iOS 4.13.0.

Advisories referenced in https://github.com/ZhouZiyi1/Vuls/blob/main/250116-IKEACN/250116-IKEACN.pdf detail the vulnerability, but no specific patch or mitigation instructions are provided in the available data. Security practitioners should advise users to update the app if newer versions are released and avoid interacting with unsolicited links from IKEA CN sources.

Details

CWE(s)
CWE-200

MITRE ATT&CK Enterprise Techniques

T1204.001 Malicious Link Execution
An adversary may rely upon a user clicking a malicious link in order to gain execution.
Why these techniques?

The vulnerability enables disclosure of sensitive user data when a victim interacts with a crafted malicious link, directly matching the Malicious Link sub-technique for user execution leading to information disclosure.

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

References