Executive brief
The Microsoft Bing app for iOS contains a security flaw that fails to properly restrict how user interface layers or frames are rendered. This allows an attacker to perform spoofing attacks, potentially tricking users into interacting with malicious content disguised as a legitimate part of the app. Such an exploit could lead to unauthorized actions or the compromise of user trust and operational integrity.
Technical details
A vulnerability classified as CWE-1021 (Improper Restriction of Rendered UI Layers or Frames) exists in the Microsoft Bing Search app for iOS. The application fails to adequately restrict the rendering of UI components, which can be leveraged by a remote, unauthenticated attacker to perform UI redressing or clickjacking. An exploit requires user interaction, typically involving a victim visiting a malicious site or clicking a link that overlays a transparent or misleading layer over the legitimate application interface. This can result in high integrity and availability impacts as the attacker can trick the user into performing unintended actions. The issue is addressed in versions 33.4.440529002 and later.
Affected products
- Microsoft Bing Search for iOS < 33.4.440529002
Timeline
- 2026-07-14: disclosed: Initial publication of the CVE record.
- 2026-07-14: advisory: Microsoft released the security update guide for this vulnerability.