CVE-2025-46279
macOS vulnerability analysis and mitigation

Overview

CVE-2025-46279 is a permissions issue in Apple's Icons subsystem that allows an installed app to identify what other apps a user has on their device. The vulnerability was disclosed on December 12, 2025, when Apple released patches across its operating system lineup. Affected platforms include iOS and iPadOS (before 18.7.3 and before 26.2), macOS Tahoe (before 26.2), tvOS (before 26.2), visionOS (before 26.2), and watchOS (before 26.2). It carries a CVSS v3.1 base score of 3.3 (Low) per NVD's assessment, though CISA-ADP assigned a separate score of 9.8 (Critical) reflecting a broader attack surface interpretation (Apple Advisory iOS 26.2, Apple Advisory iOS 18.7.3).

Technical details

The vulnerability is rooted in insufficient access controls within Apple's Icons subsystem (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor), where an app could query icon-related APIs or resources to enumerate which other applications are installed on the device without appropriate permission restrictions. Apple addressed the issue by applying additional restrictions to the permissions model governing this subsystem. Exploitation requires local access with low privileges — a malicious app already installed on the device — and no user interaction is needed. The vulnerability was discovered and reported by Duy Trần (@khanhduytran0) (Apple Advisory iOS 26.2, Apple Advisory macOS Tahoe 26.2).

Impact

Successful exploitation allows a malicious app to build a profile of other applications installed on a victim's device, which is a privacy violation that can facilitate targeted social engineering, fingerprinting, or reconnaissance for follow-on attacks. For example, knowing that a user has banking, VPN, or security apps installed could help an attacker tailor phishing campaigns or identify high-value targets. The impact is limited to confidentiality (no integrity or availability impact), and exploitation is constrained to the local device context without privilege escalation (Apple Advisory iOS 18.7.3, Apple Advisory tvOS 26.2).

Mitigation and workarounds

Apple has released patches addressing this vulnerability across all affected platforms. Users should update to iOS 18.7.3 or iPadOS 18.7.3 (for legacy devices), or iOS 26.2 / iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, and watchOS 26.2. No configuration-based workarounds have been published; updating to a patched OS version is the only recommended remediation. Users should also exercise caution when installing third-party apps from untrusted sources to reduce exposure (Apple Advisory iOS 18.7.3, Apple Advisory macOS Tahoe 26.2).

Community reactions

The vulnerability was noted in community security tracking resources such as Reddit's CVEWatch and security news aggregators shortly after disclosure. Coverage was largely bundled with the broader December 2025 Apple security update cycle, which also included more severe WebKit zero-days (CVE-2025-43529, CVE-2025-14174) that attracted greater attention. No significant standalone commentary from major security researchers specifically focused on CVE-2025-46279 has been identified beyond standard patch advisory coverage (9to5Mac).

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64776NONEN/A
  • macOS logomacOS
  • Disk Images
NoYesJul 27, 2026
CVE-2026-64775NONEN/A
  • macOS logomacOS
  • Kernel
NoYesJul 27, 2026
CVE-2026-64774NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026
CVE-2026-64772NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management