Sensitive Data Exposure in macOS and Safari by Apple
CVE-2025-46282

5.5MEDIUM

Key Information:

Vendor

Apple

Vendor
CVE Published:
17 December 2025

What is CVE-2025-46282?

This vulnerability in macOS Tahoe and Safari could potentially allow unauthorized applications to access sensitive user data due to inadequate permissions checks. The issue has been addressed in the newer versions, enhancing the security measures to prevent such data exposure and ensuring better protection for users. Users are encouraged to update to macOS Tahoe 26.2 and Safari 26.2 to mitigate the risks associated with this vulnerability.

Affected Version(s)

macOS < 26.2

Safari < 26.2

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.