CVE-2025-46300Patch(apple / ipados)

MEDIUMCVSS 5.7 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apple ipados systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. A malicious HID device may cause an unexpected process crash.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-02-12); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
ipadosiphone_osmacos

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-12: 1Mentions · 2026-05-14: 1PoC Mentioned / Linked · 2026-05-14: 1Exploit Tool / Code · 2026-05-14: 1Patch / Workaround · 2026-02-12: 1Technical Details · 2026-05-14: 102-1205-14
Signal classification2 categories
Patch
150.0%
PoC
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-121
Patch1
2026-05-141
PoC1
Full discourse2 posts
  • kokumօtօ@__kokumoto
    PoC

    Linuxでまた権限昇格の脆弱性。"Fragnasia" (CVE-2025-46300)はDirty Frag亜種で、XFRM ESP-in-TCPサブシステムのロジックバグに起因するページキャッシュメモリへの書き込みプリミティブ。PoC(攻撃の概念実証コード)公開あり。

    Post summary

    The announcement reports a privilege‑escalation vulnerability in Linux (CVE‑2025‑46300) that is a Dirty Frag variant exploiting a logic bug in XFRM ESP‑in‑TCP, and confirms the release of a Proof‑of‑Concept code.

    040833.3K
    7.6K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2025-46300 The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7.4, iOS 18.7.5 and iPadOS 18.7.5, macOS Sonoma 14.8.4. A malicious HID d… https://www.cve.org/CVERecord?id=CVE-2025-46300

    Post summary

    The vulnerability CVE-2025-46300 has been fixed in the specified macOS, iOS, and iPadOS releases, with no evidence of exploitation or PoC in the provided text.

    00000196
    56.5K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---

Explore more