
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-46298 is a memory handling vulnerability in Apple's WebKit engine that allows processing maliciously crafted web content to cause an unexpected process crash. It affects iOS, iPadOS, macOS Tahoe, Safari, tvOS, watchOS, and visionOS — all versions prior to 26.2. Apple disclosed the vulnerability on December 12, 2025, with patches released the same day; it was added to NVD on January 9, 2026. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium), reflecting a network-based, user-interaction-required attack with high availability impact (Apple Advisory iOS, Apple Advisory Safari, Feedly).
The root cause is classified as CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer), specifically a memory handling flaw in Apple's WebKit browser engine (WebKit Bugzilla: 301468). An attacker can exploit this by serving maliciously crafted web content — such as a specially constructed webpage — that triggers improper memory operations within the WebKit rendering process, leading to a process crash. Exploitation requires user interaction (e.g., visiting a malicious URL) but no special privileges or authentication. The vulnerability was discovered and reported by Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative and Nan Wang (@eternalsakura13) (Apple Advisory tvOS, Apple Advisory Safari, ZDI Advisory).
Successful exploitation causes an unexpected crash of the WebKit rendering process, resulting in a denial-of-service condition for the affected browser or application. The primary impact is on availability (CVSS availability impact: High), with no direct confidentiality or integrity compromise attributed to this specific CVE. The vulnerability affects a broad range of Apple platforms — iPhone, iPad, Mac, Apple TV, Apple Watch, and Apple Vision Pro — making the potential user population very large, though the crash impact is limited to process termination rather than code execution (Apple Advisory iOS, Apple Advisory macOS, Feedly).
com.apple.WebKit.WebContent crash reports in /Library/Logs/DiagnosticReports/ on macOS or device crash logs on iOS/iPadOS).com.apple.WebKit.WebContent or Safari processes; repeated relaunches of WebKit rendering processes in a short time window.~/Library/Logs/DiagnosticReports/ with process name com.apple.WebKit.WebContent and crash type related to memory access violations.Apple has released patches for all affected platforms in the 26.2 update cycle, released December 12, 2025. Users should update to the following versions or later: iOS 26.2, iPadOS 26.2, macOS Tahoe 26.2, Safari 26.2, tvOS 26.2, watchOS 26.2, and visionOS 26.2. No configuration-based workaround is available; upgrading is the only remediation. As an interim measure, users should avoid visiting untrusted or suspicious websites until their devices are updated (Apple Advisory iOS, Apple Advisory Safari, Apple Advisory macOS).
The December 2025 Apple WebKit update batch received significant attention due to the co-patched CVEs (CVE-2025-43529 and CVE-2025-14174) that Apple confirmed were exploited in sophisticated targeted attacks on iOS. CVE-2025-46298 itself was credited to Hossein Lotfi of Trend Micro Zero Day Initiative and Nan Wang, with ZDI publishing a formal advisory (ZDI-26-057) in February 2026. The broader update was covered by security aggregators and vulnerability tracking platforms, though CVE-2025-46298 did not independently generate significant media coverage separate from the broader WebKit patch batch (ZDI Advisory, Apple Advisory tvOS).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."