Junglewise Threat Intelligence

CVE-2025-46280: Apple macOS Tahoe out-of-bounds read

CVE-2025-46280 · Severity: info · Published 2026-05-26

Technologies: Apple macOS. Vendors: Apple.

Executive brief

A vulnerability in macOS could allow a malicious application to cause the computer to crash or restart unexpectedly. This issue affects various Mac models including Mac Studio, iMac, Mac Pro, and MacBook series. Users should update to macOS Tahoe 26 to resolve the issue and ensure system stability.

Technical details

An out-of-bounds read vulnerability exists in macOS Tahoe prior to version 26. The flaw is caused by insufficient bounds checking when processing certain data, which can be triggered by a local application. Successful exploitation allows an attacker-controlled app to cause a denial-of-service condition (system termination). Apple addressed this issue in macOS Tahoe 26 by implementing improved bounds checking.

Affected products

  • Apple macOS Tahoe before 26

Timeline

  • 2025-09-15: patched: macOS Tahoe 26 released
  • 2026-05-26: disclosed: NVD publication date

References

Related threats