CVE-2025-46277 is a low-severity logging issue affecting Apple's iOS, iPadOS, macOS, and watchOS, where an unprivileged local application could potentially access a user's Safari browsing history due to insufficient data redaction. With a CVSS score of 3.3 (Low), exploitation requires local access and has low attack complexity, primarily impacting confidentiality by exposing sensitive user data. This vulnerability is addressed in iOS 26.2, iPadOS 26.2, macOS Tahoe 26.2, and watchOS 26.2. There is currently no evidence of active exploitation, nor are there any public exploits or community discussions regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 26.2CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 26.2CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 26.2CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
< 26.2CPE matchmatch criteria | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.