CVE-2025-46298Disclosure(apple / ipados)

LOWCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apple ipados systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • safari

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-02-04); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
ipadosiphone_osmacossafaritvosvisionoswatchos

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-04: 1Mentions · 2026-02-05: 1Mentions · 2026-02-06: 1Mentions · 2026-02-12: 1PoC Mentioned / Linked · 2026-02-06: 1PoC Mentioned / Linked · 2026-02-12: 1Patch / Workaround · 2026-02-06: 1Technical Details · 2026-02-04: 1Technical Details · 2026-02-06: 1Technical Details · 2026-02-12: 102-0402-0502-0602-12
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-041
Disclosure1
2026-02-051
General1
2026-02-061
Patch1
2026-02-121
Disclosure1
Full discourse4 posts
  • Hossein Lotfi@hosselot
    Patch

    Apple updated security content of macOS Tahoe 26.2 to add one more fixed vulnerability. WebKit: CVE-2025-46298 [301468]: RCE (type confusion vulnerability during new array materialization) PoC + fix: https://github.com/WebKit/WebKit/commit/a1a6185cc83ec55675fd01a100117d0202701d28

    Post summary

    Apple patched WebKit CVE‑2025‑46298 (an RCE type‑confusion flaw) and provided a PoC link in the update.

    113071288.8K
    6.5K followersView on X
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-057|CVE-2025-46298] Apple Safari JavaScriptCore FTL New Array Materialization Type Confusion Remote Code Execution Vulnerability (CVSS 8.8; Credit: @hosselot of TrendAI ZDI) https://www.zerodayinitiative.com/advisories/ZDI-26-057/

    Post summary

    Apple Safari’s JavaScriptCore has a type‑confusion vulnerability (CVE‑2025‑46298, CVSS 8.8) that can lead to remote code execution; the ZDI advisory contains the details.

    17031185.3K
    5.3K followersView on X
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-057|CVE-2025-46298] Apple Safari JavaScriptCore FTL New Array Materialization Type Confusion Remote Code Execution Vulnerability (CVSS 8.8; Credit: @hosselot of TrendAI ZDI) https://www.zerodayinitiative.com/advisories/ZDI-26-057/

    Post summary

    Apple Safari JavaScriptCore vulnerability CVE-2025-46298 has been disclosed, presenting a type confusion RCE with CVSS 8.8. No active exploitation, patches, or PoC details are reported.

    9401281.9K
    5.3K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-1861 2 - CVE-2004-0200 3 - CVE-2026-20026 4 - CVE-2025-46298 5 - CVE-2025-68121 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The tweet lists five trending CVEs with no additional technical, exploit, or remediation information.

    00010191
    1.7K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
Appapplesafari---
OSappletvos---
OSapplevisionos---
OSapplewatchos---

Explore more