CVE-2025-46306Patch(apple / ipados)

LOWCVSS 5.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch apple ipados systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The issue was addressed with improved bounds checks. This issue is fixed in Keynote 15.1, iOS 26 and iPadOS 26, macOS Tahoe 26. Processing a maliciously crafted Keynote file may disclose memory contents.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • keynote
  • macos

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
ipadosiphone_oskeynotemacos

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-01-28: 3Patch / Workaround · 2026-01-28: 2Technical Details · 2026-01-28: 201-28
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • Cole Mahoney@colemahoney
    Patch

    Apple just patched two document-processing bugs in Pages 15.1 & Keynote 15.1 (macOS Sequoia 15.6+): - CVE-2025-46316: out-of-bounds read (improved input validation) - CVE-2025-46306: improved bounds checks Reported by Cisco Talos. Could crash apps or leak memory via malicious files. https://support.apple.com/en-us/126255 https://support.apple.com/en-us/126254

    Post summary

    Apple released patches for two document‑processing vulnerabilities in Pages and Keynote that could cause crashes or memory leaks; official support pages link to the mitigation.

    10000141
    26 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for Apple iOS and other products (CVE-2025-46306) https://vuldb.com/?id.343273

    Post summary

    The post announces that CVE‑2025‑46306, a severe vulnerability affecting Apple iOS and other products, has been disclosed, linking to a vulnerability database for further details.

    0000085
    2.1K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2025-46306 The issue was addressed with improved bounds checks. This issue is fixed in macOS Tahoe 26, Keynote 15.1, iOS 26 and iPadOS 26. Processing a maliciously crafted Keyno… https://www.cve.org/CVERecord?id=CVE-2025-46306

    Post summary

    The post reports that CVE‑2025‑46306 has been addressed with improved bounds checks and is fixed in recent Apple operating systems and Keynote.

    00000178
    56.5K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
Appapplekeynote---
OSapplemacos---

Explore more