CVE-2025-46276
macOS vulnerability analysis and mitigation

Overview

CVE-2025-46276 is an information disclosure vulnerability in the Messages component of multiple Apple operating systems that allows a locally installed app to access sensitive user data. It was discovered by Rosyna Keller of Totally Not Malicious Software and disclosed on December 12, 2025, when Apple released patches. Affected versions include iOS/iPadOS prior to 18.7.3 and 26.2, macOS Sonoma prior to 14.8.3, macOS Sequoia prior to 15.7.3, macOS Tahoe 26.2, visionOS 26.2, and watchOS 26.2. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) per NIST NVD, though CISA-ADP assessed it lower at 3.3 (Low) (Apple Advisory iOS 26.2, Apple Advisory macOS Sequoia, Apple Advisory macOS Sonoma).

Technical details

The vulnerability is classified as an information disclosure issue (CWE categorized as NVD-CWE-noinfo due to insufficient public detail) residing in the Messages component across Apple platforms. Apple addressed it by implementing improved privacy controls, suggesting the root cause involved inadequate access restrictions or data exposure within the Messages subsystem that permitted an app to read sensitive user data it should not have been able to access. The attack vector is local (AV:L), requiring low privileges and no user interaction, meaning a malicious app already installed on the device could silently exploit this flaw without any additional user action. No public proof-of-concept code or detailed technical write-up has been identified (Apple Advisory macOS Sequoia, Apple Advisory macOS Sonoma).

Impact

Successful exploitation allows a malicious app to access sensitive user data stored or processed by the Messages component, resulting in a high confidentiality impact with no effect on integrity or availability. The scope of exposed data is not fully detailed publicly, but given the Messages context, this could include message content, contact information, or other private communications data. There is no evidence of lateral movement potential, as the vulnerability is locally scoped and does not enable privilege escalation or remote access on its own (Apple Advisory iOS 26.2, Apple Advisory macOS Sequoia).

Mitigation and workarounds

Apple has released patches addressing this vulnerability across all affected platforms. Users should update to the following versions or later: iOS 18.7.3, iPadOS 18.7.3, iOS 26.2, iPadOS 26.2, macOS Sonoma 14.8.3, macOS Sequoia 15.7.3, macOS Tahoe 26.2, visionOS 26.2, and watchOS 26.2. No configuration-based workarounds have been published; updating to a patched OS version is the only recommended remediation. Users should apply updates via System Settings > General > Software Update on macOS/iOS (Apple Advisory iOS 26.2, Apple Advisory macOS Sequoia, Apple Advisory macOS Sonoma).

Community reactions

The December 12, 2025 Apple security release received broad media coverage primarily due to the simultaneous disclosure of two actively exploited WebKit zero-days (CVE-2025-43529 and CVE-2025-14174) in the same update batch, which overshadowed CVE-2025-46276 in public discussion. Security outlets such as CyberSecurityNews and CyberInsider covered the overall release with emphasis on the zero-day WebKit flaws rather than this specific information disclosure issue. No notable researcher commentary specific to CVE-2025-46276 beyond the discoverer credit (Rosyna Keller of Totally Not Malicious Software) has been identified (Apple Advisory iOS 26.2).

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64776NONEN/A
  • macOS logomacOS
  • Disk Images
NoYesJul 27, 2026
CVE-2026-64775NONEN/A
  • macOS logomacOS
  • Kernel
NoYesJul 27, 2026
CVE-2026-64774NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026
CVE-2026-64772NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management