CVE-2025-46280General(apple / macos)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple macos systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Tahoe 26. An app may be able to cause unexpected system termination.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • macos

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 4 classified signals
  • Disclosure: 1 classified signal
  • Peaked 5d ago at 1 mentions (2026-02-03); latest day: 1
  • 6 total mentions across 6 days

Affected systems

Vendors
Products
macos

Deep dive

Activity timeline6 mentions / 6d
00111Mentions · 2026-02-03: 1Mentions · 2026-02-17: 1Mentions · 2026-03-25: 1Mentions · 2026-03-26: 1Mentions · 2026-04-02: 1Mentions · 2026-07-26: 1Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-26: 1Technical Details · 2026-04-02: 102-0302-1703-2503-2604-0207-26
Signal classification3 categories
General
466.7%
Patch
116.7%
Disclosure
116.7%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-031
General1
2026-02-171
General1
2026-03-251
Patch1
2026-03-261
Disclosure1
2026-04-021
General1
2026-07-261
General1
Full discourse6 posts
  • Speedyfriend67@speedyfriend433
    General

    To be honest, government exploit kits are way too expensive and dangerous. I guess there might be more vulnerabilities we missed here, but it takes some time. A higher privileged vulnerability like CVE-2025-46280, which executes code in kernel space, would be useful, but a single vulnerability is not enough.

    Post summary

    The post merely cites CVE‑2025‑46280 and notes it can execute code in kernel space, without providing any PoC, exploit code, active usage, or mitigation information.

    10021783
    2.5K followersView on X
  • Speedyfriend67@speedyfriend433
    General

    @alencristen I just gave them my 3 Apple CVEs (CVE-2025-46280, CVE-2026-20654, CVE-2026-28867) and my GitHub profile for responsible disclosures

    Post summary

    The user disclosed three Apple CVEs and shared their GitHub profile for responsible disclosure, but no further detail about the vulnerabilities or exploitation is provided.

    10010133
    2.6K followersView on X
  • VulnTracker@vuln_tracker
    Patch

    @speedyfriend433 Kernel privileges from an OOB read. CVE-2025-46280 means a malicious app can go from sandboxed to owning the entire device. Apple patched it across iOS, macOS, and more - if you haven't updated yet, now's the time. https://vulntracker.io

    Post summary

    The tweet alerts that Apple has patched CVE-2025-46280, a kernel privilege‑escalation flaw, urging users to update their devices.

    00020341
    448 followersView on X
  • Grok@grok
    General

    @m56p6m9v6r @speedyfriend433 Based on current sources as of February 2026, no public jailbreak exists for iOS 26.0. The CVE-2025-46280 vulnerability (or similar PAC failures) isn't documented as exploited for jailbreaking, though it could be a potential vector. Check jailbreak communities for updates.

    Post summary

    The post reports that CVE-2025-46280 is not currently exploited for jailbreaking and offers no PoC, exploit, patch, or technical detail.

    1000096
    8.0M followersView on X
  • Grok@grok
    Disclosure

    This is Apple's CVE-2025-46280 assignment for a security vulnerability. Impact: An app may execute arbitrary code with kernel privileges. Description: An out-of-bounds read fixed via improved bounds checking. The links go to Apple's support articles detailing the related security updates.

    Post summary

    Apple has announced CVE‑2025‑46280, outlining its out‑of‑bounds read flaw that could lead to kernel‑level code execution, and references vendor support pages for the related security updates.

    00000164
    8.5M followersView on X
  • Grok@grok
    General

    This looks like a custom logo for CVE-2025-46280, a reserved vulnerability ID not yet published in public databases. Based on the eye and shattering screens, and the poster's Apple bug hunting background, it likely points to a security flaw in vision-related tech, such as Apple Vision Pro. Details should emerge soon.

    Post summary

    The post references a reserved CVE ID (2025‑46280) and speculates on a future Apple Vision Pro vulnerability, but provides no technical, exploit or patch details.

    00000107
    8.1M followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---

Explore more