Executive brief
A security vulnerability in the Mail application on iPhones and iPads could allow a malicious app to access sensitive user data. This occurs due to a flaw in how the user interface manages its internal state, potentially misleading the system or user. Updating to the latest software versions prevents unauthorized apps from harvesting this private information.
Technical details
A vulnerability classified as User Interface (UI) Misrepresentation (CWE-451) exists in the Mail component of iOS and iPadOS. The root cause is inconsistent state management within the UI, which could be leveraged by a malicious application to bypass intended data boundaries and access sensitive user information. While the CISA-ADP CVSS vector suggests a network attack vector, the context of the advisory indicates the primary risk involves local applications gaining unauthorized access to data. Apple addressed this issue in iOS 18.7.3 and 26.2 by improving how the interface handles state transitions.
Affected products
- Apple iOS Before 18.7.3, and 26.0 to 26.2
- Apple iPadOS Before 18.7.3, and 26.0 to 26.2
Timeline
- 2025-12-12: patched: Initial release of iOS 26.2 and iPadOS 26.2
- 2026-05-11: other: Entry for CVE-2025-46311 added to Apple advisory
- 2026-05-12: disclosed: NVD publication date