
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-46283 is a logic issue in the CoreServices component of Apple macOS that allows a locally installed app to access sensitive user data without proper authorization. The vulnerability was disclosed on December 12, 2025, and affects macOS versions prior to Tahoe 26.2 and macOS Sonoma prior to 14.8.4. It was reported by an anonymous researcher and carries a CVSS v3.1 base score of 5.5 (Medium) (Apple Advisory Tahoe, Apple Advisory Sonoma).
The root cause is a logic flaw in macOS CoreServices (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor) that was addressed with improved validation. The attack vector is local, requiring a low-privileged app already running on the system to exploit the flaw — no user interaction is needed. The vulnerability allows an app to bypass expected access controls within CoreServices and read sensitive user data it should not be permitted to access (Apple Advisory Tahoe, Apple Advisory Sonoma).
Successful exploitation results in unauthorized disclosure of sensitive user data accessible through the CoreServices framework, impacting confidentiality with no effect on integrity or availability. A malicious or compromised app running with standard user privileges could silently read protected data, potentially including personal information managed by CoreServices. There is no evidence of lateral movement capability or remote exploitation from this vulnerability alone (Apple Advisory Tahoe, Apple Advisory Sonoma).
Apple has released patches addressing this vulnerability in macOS Tahoe 26.2 (released December 12, 2025) and macOS Sonoma 14.8.4 (released February 11, 2026). Users should update to these versions or later immediately via System Settings > Software Update. No configuration-based workarounds have been published by Apple; upgrading is the only recommended remediation (Apple Advisory Tahoe, Apple Advisory Sonoma).
The vulnerability was included in Apple's December 2025 security release, which was covered by CIS in a multi-vulnerability advisory noting the potential for arbitrary code execution across Apple products in that batch (CIS Advisory). The SANS Internet Storm Center also noted the December 2025 Apple patch release. No significant independent researcher commentary or social media discussion specific to CVE-2025-46283 has been identified beyond routine vulnerability tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."