CVE-2025-46285General(apple / macos)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple macos systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An integer overflow was addressed by adopting 64-bit timestamps. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. An app may be able to gain root privileges.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • macos

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-02-04); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
macos

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-04: 2Mentions · 2026-04-18: 1Mentions · 2026-10-08: 1Patch / Workaround · 2026-02-04: 1Technical Details · 2026-02-04: 1Technical Details · 2026-04-18: 102-0404-1810-08
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-042
Disclosure1General1
2026-04-181
General1
Full discourse4 posts
  • VulnTracker@vuln_tracker
    General

    @hermes_tool1 You now can see the full details about CVE-2025-46285 from https://vulntracker.io/cves/CVE-2025-46285 FOR FREE

    Post summary

    The tweet merely directs users to a vulnerability tracker page for CVE-2025-46285, providing no further technical or actionable information.

    000821.5K
    333 followersView on X
  • Grok@grok
    Disclosure

    الترجمة: "لدى iOS 26.1 مرشح لاستغلال جذري: CVE-2025-46285 لا يمكنه توفير تصحيح أخطاء النواة أو jailbreak، لكنه قد يكون مفيداً كخطوة أولى لتعزيز الرؤية في داخليات iOS، والبحث عن خطأ يمكنه ذلك." التفسير: هذا يشير إلى ثغرة أمنية (CVE-2025-46285) في iOS 26.1، تتعلق بتجاوز عددي في النواة يسمح لتطبيق بالحصول على صلاحيات جذرية. تم إصلاحها باستخدام تواقيت 64 بت. الثغرة متوفرة في أجهزة مثل iPhone 11 فما فوق وiPad محددة. ليست كافية للـjailbreak الكامل أو تصحيح النواة، لكنها قد تساعد في اكتشاف ثغرات أفضل للوصول إلى داخليات النظام. اكتشفها باحثون من Alibaba.

    Post summary

    CVE-2025-46285 is a numeric overflow in iOS 26.1’s kernel that allows an app to gain root privileges, but it does not enable a full jailbreak; the issue has been patched via 64‑bit signatures.

    10000235
    8.1M followersView on X
  • DFIR Lab@DFIR_Lab

    🚨 HIGH: CVE-2025-46285 (CVSS 7.8) Integer overflow in Apple products allows apps to gain root privileges. Fixed in iOS 18.7.3/26.2, macOS Sequoia 15.7.3, Sonoma 14.8.3, Tahoe 26.2, tvOS/visionOS/watchOS 26.2. Update immediately. #CVE #PatchNow https://t.co/WFks46jmBx

    0000030
    144 followersView on X
  • appaudix@AppAudix
    General

    Stop assuming iOS patches itself. 400 million iPhones still running CVE-2025-46285 (kernel privilege escalation). Your app's sandbox? Gone. Keychain? Readable. Build defense layers that don't depend on users updating their phones. Pro is free for ... https://appaudix.com/blog/ios-zero-days-why-your-app-cant-trust-the-device https://t.co/oqhntCPpa8

    Post summary

    The post warns that 400 million iPhones still have the unpatched CVE-2025-46285 kernel privilege escalation, urging developers to design defenses independent of device updates.

    00000466
    2 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---

Explore more