CVE-2025-46292 is a medium-severity vulnerability affecting Apple iOS and iPadOS that could allow an installed application to access user-sensitive data due to insufficient entitlement checks. With a CVSS score of 5.5, exploitation requires local access and low privileges but does not need user interaction, leading to a high confidentiality impact. This vulnerability is not currently listed on CISA's KEV catalog, has no known public exploits or proof-of-concept code, and shows no community discussion or media coverage, indicating a low immediate exploitation risk. Apple has addressed this issue with additional entitlement checks in iOS 18.7.3, iPadOS 18.7.3, and subsequent versions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 18.7.3CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
>= 26.0, < 26.2CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 18.7.3CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
>= 26.0, < 26.2CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.