CVE-2025-46285 addresses an integer overflow vulnerability in multiple Apple operating systems, including macOS, iOS, and iPadOS, which was fixed by adopting 64-bit timestamps. This vulnerability carries a CVSS score of 7.8 HIGH, indicating that a local attacker with low privileges could exploit it with low complexity to allow an application to gain root privileges, resulting in high impact to confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, no public exploit code available in common repositories, and minimal community discussion or media coverage regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 14.8.3CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
>= 15.0, < 15.7.3CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
About the security content of iOS 26.2 and iPadOS 26.2 - Apple Support
About the security content of iOS 18.7.3 and iPadOS 18.7.3 - Apple Support
About the security content of macOS Tahoe 26.2 - Apple Support
About the security content of macOS Sequoia 15.7.3 - Apple Support
About the security content of macOS Sonoma 14.8.3 - Apple Support
About the security content of tvOS 26.2 - Apple Support
About the security content of watchOS 26.2 - Apple Support
About the security content of visionOS 26.2 - Apple Support