CVE-2025-46285
macOS vulnerability analysis and mitigation

Overview

CVE-2025-46285 is a kernel integer overflow vulnerability in multiple Apple operating systems that allows a local app to gain root privileges. The flaw was discovered by Kaitao Xie and Xiaolong Bai of Alibaba Group and disclosed on December 12, 2025, when Apple released patches across its product lineup. Affected versions include macOS Sonoma prior to 14.8.3, macOS Sequoia prior to 15.7.3, iOS/iPadOS prior to 18.7.3, and earlier versions of tvOS, visionOS, and watchOS. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Apple Advisory macOS Sequoia, Apple Advisory iOS 26.2).

Technical details

The vulnerability is classified as CWE-190 (Integer Overflow or Wraparound) and resides in the Apple kernel component. The root cause is the use of insufficiently sized (non-64-bit) timestamp values in kernel code, which can overflow and be manipulated by a malicious application to corrupt kernel data structures and escalate privileges to root. Exploitation requires local access with low privileges and no user interaction, making it suitable for use as a privilege escalation stage in a broader attack chain. Apple addressed the issue by adopting 64-bit timestamps to prevent the overflow condition (Apple Advisory macOS Sequoia, Apple Advisory macOS Sonoma).

Impact

Successful exploitation allows a low-privileged local application to gain root (superuser) privileges on the affected device, resulting in complete compromise of confidentiality, integrity, and availability. An attacker with root access can install persistent malware, access all user data and credentials, disable security controls, and use the compromised device as a pivot point for further attacks within a network. The vulnerability affects a broad range of Apple platforms including macOS, iOS, iPadOS, tvOS, visionOS, and watchOS (Apple Advisory iOS 26.2, Apple Advisory visionOS 26.2).

Mitigation and workarounds

Apple has released patches addressing CVE-2025-46285 across all affected platforms. Users should update to the following versions or later: macOS Sonoma 14.8.3, macOS Sequoia 15.7.3, macOS Tahoe 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, tvOS 26.2, visionOS 26.2, and watchOS 26.2. No configuration-based workaround is available; patching is the only remediation. As a defense-in-depth measure, organizations should limit installation of untrusted third-party applications and enforce least-privilege policies on managed devices (Apple Advisory macOS Sequoia, Apple Advisory macOS Sonoma, Apple Advisory iOS 26.2).

Community reactions

The December 12, 2025 Apple security update received significant media coverage primarily due to the co-patched WebKit zero-days (CVE-2025-43529 and CVE-2025-14174) that Apple confirmed were exploited in sophisticated targeted attacks against iPhone users. Publications including Forbes, CyberSecurityNews, GBHackers, and CyberInsider reported on the update batch with urgency, urging immediate patching. CVE-2025-46285 itself was noted as a high-severity kernel privilege escalation flaw within these broader coverage pieces. The CIS also issued an advisory noting multiple vulnerabilities in Apple products that could allow arbitrary code execution (Apple Advisory iOS 26.2).

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64776NONEN/A
  • macOS logomacOS
  • Disk Images
NoYesJul 27, 2026
CVE-2026-64775NONEN/A
  • macOS logomacOS
  • Kernel
NoYesJul 27, 2026
CVE-2026-64774NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026
CVE-2026-64772NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management