CVE-2025-46291
macOS vulnerability analysis and mitigation

Overview

CVE-2025-46291 is a Gatekeeper bypass vulnerability in Apple macOS affecting the LaunchServices component. A logic issue in input validation allows a malicious application to bypass Gatekeeper security checks, which are designed to ensure only trusted software runs on macOS. The vulnerability was discovered by security researcher Kenneth Chew and disclosed by Apple on December 12, 2025, with a fix included in macOS Tahoe 26.2. It carries a CVSS v3.1 base score of 7.8 (High) per NIST NVD, though CISA-ADP assessed it at 5.5 (Medium) reflecting a more constrained impact scope (Apple Advisory, NVD).

Technical details

The vulnerability is rooted in a logic flaw within the LaunchServices component of macOS, classified as CWE-693 (Protection Mechanism Failure). Gatekeeper is a macOS security feature that enforces code signing and verifies that downloaded software is from an identified developer before allowing execution; the flawed validation logic in LaunchServices can be exploited by a locally-executed application to circumvent these checks. The attack vector is local, requiring low privileges and no user interaction, suggesting a malicious app already present on the system could silently bypass Gatekeeper enforcement. Apple addressed the issue with improved validation logic in macOS Tahoe 26.2 (Apple Advisory, NVD).

Impact

Successful exploitation allows a malicious application to bypass Gatekeeper checks, undermining a core macOS defense-in-depth control that prevents unsigned or untrusted code from executing. This could enable an attacker to run unauthorized or malicious software without triggering the expected security warnings or blocks, potentially facilitating malware installation, persistence, or further privilege escalation. The integrity impact is high, as the security boundary protecting users from untrusted executables is effectively nullified; confidentiality and availability impacts are also rated high by NIST, though CISA-ADP's assessment limits the primary impact to integrity (NVD, Apple Advisory).

Mitigation and workarounds

Apple has released a fix in macOS Tahoe 26.2, released December 12, 2025. Users and administrators should update to macOS Tahoe 26.2 or later to remediate this vulnerability. No configuration-based workarounds have been published by Apple. Organizations should prioritize patching macOS endpoints, particularly those where untrusted or third-party applications may be executed (Apple Advisory).

Community reactions

The CIS (Center for Internet Security) issued an advisory noting multiple vulnerabilities in Apple products patched in this release could allow for arbitrary code execution, recommending prompt updates (CIS Advisory). The vulnerability was also noted in the SANS Internet Storm Center diary covering the December 2025 Apple patch batch (SANS ISC). Community reaction has been limited given the low EPSS score and absence of public exploit code.

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64776NONEN/A
  • macOS logomacOS
  • Disk Images
NoYesJul 27, 2026
CVE-2026-64775NONEN/A
  • macOS logomacOS
  • Kernel
NoYesJul 27, 2026
CVE-2026-64774NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026
CVE-2026-64772NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management