This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. Visiting a malicious website may lead to user interface spoofing.
No PoCs from references.
- https://github.com/RNando1337/RNando1337
- https://github.com/fkie-cad/nvd-json-data-feeds