PatchSiren cyber security CVE debrief
CVE-2025-46307 Apple CVE debrief
A logic issue in macOS Tahoe 26 could allow an app to access sensitive user data. Apple addressed this with improved restrictions. The vulnerability was published on May 26, 2026, with no CVSS score or severity assigned. No known exploitation in the wild has been reported.
- Vendor
- Apple
- Product
- macOS
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-26
- Original CVE updated
- 2026-05-27
- Advisory published
- 2026-05-26
- Advisory updated
- 2026-05-27
Who should care
macOS administrators and users running pre-Tahoe 26 versions should prioritize patching. Organizations with strict data access controls should review application permissions. Security teams monitoring for macOS vulnerabilities should track this for potential inclusion in threat models once additional technical details emerge.
Technical summary
This vulnerability stems from a logic issue in macOS that insufficiently restricted application access to sensitive user data. The fix implemented in macOS Tahoe 26 adds improved restrictions to prevent unauthorized data access. No technical details about the specific attack vector or affected components have been disclosed. The absence of CVSS scoring and detailed weakness classification limits precise risk assessment.
Defensive priority
medium
Recommended defensive actions
- Apply macOS Tahoe 26 or later to affected systems
- Review application permissions and sandboxing configurations
- Monitor for unusual application access to sensitive user data
- Await Apple security advisory for additional technical details
Evidence notes
The CVE description confirms this is a logic issue fixed in macOS Tahoe 26. The Apple security advisory (reference 125110) is cited as the primary source. No CVSS vector, CWE classification, or CPE criteria were available in the source data. Vendor identification as Apple is based on reference domain candidate evidence with low confidence and requires review.
Official resources
-
CVE-2025-46307 CVE record
CVE.org
-
CVE-2025-46307 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
Apple disclosed this vulnerability through its security advisory channel. The issue was resolved in macOS Tahoe 26 with improved restrictions to prevent unauthorized access to sensitive user data.