CVE-2025-46283
macOS vulnerability analysis and mitigation

Overview

CVE-2025-46283 is a logic issue in the CoreServices component of Apple macOS that allows a locally installed app to access sensitive user data without proper authorization. The vulnerability was disclosed on December 12, 2025, and affects macOS versions prior to Tahoe 26.2 and macOS Sonoma prior to 14.8.4. It was reported by an anonymous researcher and carries a CVSS v3.1 base score of 5.5 (Medium) (Apple Advisory Tahoe, Apple Advisory Sonoma).

Technical details

The root cause is a logic flaw in macOS CoreServices (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor) that was addressed with improved validation. The attack vector is local, requiring a low-privileged app already running on the system to exploit the flaw — no user interaction is needed. The vulnerability allows an app to bypass expected access controls within CoreServices and read sensitive user data it should not be permitted to access (Apple Advisory Tahoe, Apple Advisory Sonoma).

Impact

Successful exploitation results in unauthorized disclosure of sensitive user data accessible through the CoreServices framework, impacting confidentiality with no effect on integrity or availability. A malicious or compromised app running with standard user privileges could silently read protected data, potentially including personal information managed by CoreServices. There is no evidence of lateral movement capability or remote exploitation from this vulnerability alone (Apple Advisory Tahoe, Apple Advisory Sonoma).

Mitigation and workarounds

Apple has released patches addressing this vulnerability in macOS Tahoe 26.2 (released December 12, 2025) and macOS Sonoma 14.8.4 (released February 11, 2026). Users should update to these versions or later immediately via System Settings > Software Update. No configuration-based workarounds have been published by Apple; upgrading is the only recommended remediation (Apple Advisory Tahoe, Apple Advisory Sonoma).

Community reactions

The vulnerability was included in Apple's December 2025 security release, which was covered by CIS in a multi-vulnerability advisory noting the potential for arbitrary code execution across Apple products in that batch (CIS Advisory). The SANS Internet Storm Center also noted the December 2025 Apple patch release. No significant independent researcher commentary or social media discussion specific to CVE-2025-46283 has been identified beyond routine vulnerability tracking.

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64776NONEN/A
  • macOS logomacOS
  • Disk Images
NoYesJul 27, 2026
CVE-2026-64775NONEN/A
  • macOS logomacOS
  • Kernel
NoYesJul 27, 2026
CVE-2026-64774NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026
CVE-2026-64772NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management