Junglewise Threat Intelligence

CVE-2025-46308: Apple iOS and macOS authorization bypass via improper state management

CVE-2025-46308 · Severity: info · CVSS 0 · Published 2026-06-11

Technologies: Apple iPadOS, Apple macOS Sequoia. Vendors: Apple.

Executive brief

An authorization vulnerability in Apple operating systems could allow a malicious application to access sensitive user information. This issue affects iPhones, iPads, and Mac computers. By exploiting this flaw, a rogue app could bypass certain security checks to leak private data, potentially compromising user privacy.

Technical details

An authorization vulnerability exists in Apple's state management logic across multiple operating systems. The flaw allows a locally installed malicious application to bypass intended authorization constraints and access sensitive user data. Apple addressed the root cause by improving state management within the affected components. The vulnerability is resolved in iOS 18.4, iPadOS 18.4, and macOS Sequoia 15.4. While specific technical details of the 'state management' failure are not disclosed, the impact is categorized as a sensitive information leak.

Affected products

  • Apple iOS Before 18.4
  • Apple iPadOS Before 18.4
  • Apple macOS Sequoia Before 15.4

Timeline

  • 2025-03-31: patched: Initial release of fixes in iOS 18.4 and macOS 15.4
  • 2026-06-11: disclosed: CVE record published

References

Related threats