PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-46307 Apple CVE debrief

A logic issue in macOS Tahoe 26 could allow an app to access sensitive user data. Apple addressed this with improved restrictions. The vulnerability was published on May 26, 2026, with no CVSS score or severity assigned. No known exploitation in the wild has been reported.

Vendor
Apple
Product
macOS
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-26
Original CVE updated
2026-07-23
Advisory published
2026-05-26
Advisory updated
2026-07-23

Who should care

macOS administrators and users running pre-Tahoe 26 versions should prioritize patching. Organizations with strict data access controls should review application permissions. Security teams monitoring for macOS vulnerabilities should track this for potential inclusion in threat models once additional technical details emerge.

Technical summary

This vulnerability stems from a logic issue in macOS that insufficiently restricted application access to sensitive user data. The fix implemented in macOS Tahoe 26 adds improved restrictions to prevent unauthorized data access. No technical details about the specific attack vector or affected components have been disclosed. The absence of CVSS scoring and detailed weakness classification limits precise risk assessment.

Defensive priority

medium

Recommended defensive actions

  • Apply macOS Tahoe 26 or later to affected systems
  • Review application permissions and sandboxing configurations
  • Monitor for unusual application access to sensitive user data
  • Await Apple security advisory for additional technical details

Evidence notes

The CVE description confirms this is a logic issue fixed in macOS Tahoe 26. The Apple security advisory (reference 125110) is cited as the primary source. No CVSS vector, CWE classification, or CPE criteria were available in the source data. Vendor identification as Apple is based on reference domain candidate evidence with low confidence and requires review.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-46307 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-46307

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-46307 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-46307

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.