CVE-2025-46279

Published Dec 17, 2025

Last updated a month ago

CVSS low 3.3
Apple Kernel

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-46279 is a vulnerability that affects Apple products. Specifically, it is a permissions issue in the Kernel that was addressed with additional restrictions. It impacts devices including iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later. Duy Trần (@khanhduytran0) is credited with reporting this vulnerability. Successful exploitation of CVE-2025-46279 could allow an app to elevate privileges or gain root privileges. The vulnerability is addressed in macOS Tahoe 26.2, as well as iOS and iPadOS 26.2.

Description
A permissions issue was addressed with additional restrictions. This issue is fixed in watchOS 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, tvOS 26.2. An app may be able to identify what other apps a user has installed.
Source
product-security@apple.com
NVD status
Modified
Products
ipados, iphone_os, macos, tvos, visionos, watchos

Risk scores

CVSS 3.1

Type
Primary
Base score
3.3
Impact score
1.4
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity
LOW

Weaknesses

nvd@nist.gov
NVD-CWE-noinfo
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-200

Social media

Hype score
Not currently trending

Configurations