
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-46277 is a logging information disclosure vulnerability in Apple's Screen Time component that allows a local app to access a user's Safari browsing history without user interaction. The flaw stems from insufficient data redaction in log files (CWE-532). It affects iOS, iPadOS, macOS Tahoe, and watchOS prior to version 26.2. Apple disclosed and patched the vulnerability on December 12, 2025, with NVD publication on December 17, 2025. The CVSS v3.1 base score is 3.3 (Low) per NIST, though CISA-ADP assessed it at 5.5 (Medium) due to the potential for complete Safari history disclosure (Apple iOS Advisory, Apple macOS Advisory, Apple watchOS Advisory).
The vulnerability is classified as CWE-532 (Insertion of Sensitive Information into Log File) and resides in the Screen Time component across Apple platforms. The root cause is that Screen Time's logging subsystem failed to adequately redact Safari browsing history data before writing it to log files, leaving that data accessible to other apps with local access. Exploitation requires only local access with low privileges and no user interaction — an installed app can read the log entries containing Safari history. The vulnerability was discovered and reported by security researcher Kirin (@Pwnrin) (Apple iOS Advisory, Apple macOS Advisory).
Successful exploitation results in unauthorized disclosure of a user's Safari browsing history, representing a confidentiality breach with no integrity or availability impact. Any locally installed app with low privileges could silently read browsing history from system logs without requiring user interaction. The scope is limited to the local device, but the exposed data could reveal sensitive personal information such as visited URLs, potentially enabling targeted phishing, profiling, or privacy violations (Apple iOS Advisory, Apple macOS Advisory, Apple watchOS Advisory).
Apple has released patches addressing this vulnerability in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, and watchOS 26.2, all released on December 12, 2025. Users should update all affected Apple devices to these versions or later via the standard software update mechanism. No configuration-based workaround is available; upgrading is the only remediation. Additionally, restricting installation of untrusted third-party apps reduces exposure risk on unpatched devices (Apple iOS Advisory, Apple macOS Advisory, Apple watchOS Advisory).
The vulnerability was part of a broader December 2025 Apple security update that received general media coverage, primarily focused on more severe WebKit zero-days patched in the same release. CVE-2025-46277 itself did not generate significant standalone commentary, though security outlets such as 9to5Mac and Lifehacker covered the iOS 26.2 update broadly. The CIS issued an advisory noting multiple vulnerabilities in Apple products addressed in this update cycle (CIS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."