
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-46287 is a FaceTime caller ID spoofing vulnerability affecting multiple Apple platforms, classified as a User Interface (UI) Misrepresentation of Critical Information flaw (CWE-451). The vulnerability stems from an inconsistent user interface issue in the Calling Framework and Call History components, allowing an attacker to spoof their FaceTime caller ID as displayed to the recipient. It was disclosed on December 12, 2025, and affects iOS/iPadOS prior to 18.7.3 and 26.2, macOS Sonoma prior to 14.8.3, macOS Sequoia prior to 15.7.3, macOS Tahoe 26.2, visionOS 26.2, and watchOS 26.2. The CVSS v3.1 base score is 6.5 (Medium) per NVD, though CISA-ADP assessed it at 9.8 (Critical) (Apple Advisory iOS 26.2, macOS Sequoia Advisory, macOS Sonoma Advisory).
The vulnerability is rooted in improper state management within Apple's Calling Framework and Call History subsystems, leading to an inconsistent UI representation of the caller's identity during FaceTime calls (CWE-451). The flaw allows an attacker to manipulate or misrepresent the caller ID displayed to the call recipient without requiring any user interaction or elevated privileges, exploitable over the network. The fix involved improved state management to ensure the displayed caller ID accurately reflects the actual caller. The vulnerability was discovered by an anonymous researcher and Riley Walz (macOS Sequoia Advisory, macOS Sonoma Advisory, Apple Advisory iOS 26.2).
Successful exploitation allows an attacker to impersonate a trusted contact or entity during a FaceTime call by spoofing the displayed caller ID, posing significant social engineering and fraud risks. The primary impact is on integrity and confidentiality — victims may be deceived into sharing sensitive information or taking actions based on a falsely displayed identity. While there is no direct availability impact, the spoofing capability could facilitate targeted phishing, vishing (voice phishing), or scam attacks against individuals across iPhone, iPad, Mac, Apple Vision Pro, and Apple Watch devices (Apple Advisory iOS 26.2, macOS Sequoia Advisory).
Apple has released patches addressing CVE-2025-46287 across all affected platforms. Users should update to the following versions or later: iOS 18.7.3, iPadOS 18.7.3, iOS 26.2, iPadOS 26.2, macOS Sonoma 14.8.3, macOS Sequoia 15.7.3, macOS Tahoe 26.2, visionOS 26.2, and watchOS 26.2. No configuration-based workarounds have been published; updating to a patched OS version is the only recommended remediation. Updates can be applied via Settings > General > Software Update on iOS/iPadOS, or System Settings > General > Software Update on macOS (macOS Sequoia Advisory, macOS Sonoma Advisory, Apple Advisory iOS 26.2).
Coverage of this vulnerability was largely bundled with Apple's broader December 2025 security update cycle, which also included more severe WebKit zero-days. Media outlets such as 9to5Mac and Lifehacker highlighted the FaceTime spoofing flaw in the context of the broader iOS 26.2 and macOS update releases, with Lifehacker Australia specifically noting the scam risk to iPhone users. The CIS issued an advisory noting multiple vulnerabilities in Apple products patched in this release cycle (9to5Mac, CIS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."