CVE-2025-46284: Race Condition
A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An app may be able to gain root privileges.
Other sources
AirPort. A permissions issue was addressed with additional restrictions.
— Apple
AMD. A buffer overflow was addressed with improved bounds checking.
— Apple
AppKit. The issue was resolved by blocking unsigned services from launching on Intel Macs.
— Apple
Apple Neural Engine. An out-of-bounds access issue was addressed with improved bounds checking.
— Apple
Apple Online Store Kit. A permissions issue was addressed with additional restrictions.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.7 - Upgrade
Upgrade
macOS Sequoiato a version that resolves this vulnerability.Fixed in 15.7 - Upgrade
Upgrade
macOS Tahoeto a version that resolves this vulnerability.Fixed in 26 - Remove
Remove
vulnerable codefrom your environment.Remove the vulnerable code, as described for multiple issues ("addressed by removing the vulnerable code").
- Configuration
Block unsigned services from launching on Intel Macs (described as the resolution for this issue on Intel Macs).
Intel Macs Block unsigned services from launching = enabled - Configuration
Apply the additional AppSandbox sandbox restrictions referenced in the material ("access issue... addressed with additional sandbox restrictions").
AppSandbox Additional sandbox restrictions = applied - Configuration
Add the additional entitlement checks mentioned in the material ("addressed with additional entitlement checks").
permissions/entitlements enforcement Additional entitlement checks = applied - Configuration
Improve authorization state management as referenced ("authorization issue... improved state management").
authorization logic Improved state management = applied - Configuration
Improve data redaction for logging as referenced ("logging issue... improved data redaction").
data redaction/logging Improved data redaction = applied - Configuration
Apply improved bounds checking/validation and related checks described in the material (covers improved bounds checking for buffer/out-of-bounds cases and improved input validation for out-of-bounds write).
input handling Improved input validation / checks = applied - Configuration
Improve validation of symlinks as referenced ("improved validation of symlinks").
symlink handling Improved validation of symlinks = applied - Configuration
Apply the improved logic checks and validation described in the material ("logic issue... improved checks" and "logic issue... improved validation").
logic checks Improved checks / improved validation = applied - Compensating control
Address the described race conditions by applying additional validation and improved state handling ("race condition... additional validation" and "race condition... improved state handling").
- Compensating control
Apply additional code-signing restrictions to mitigate the downgrade issue ("downgrade issue was addressed with additional code-signing restrictions").
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-43288
- CVE-2025-43208
- CVE-2025-43312
- CVE-2025-43321
- CVE-2025-43344
- CVE-2025-31268
- CVE-2025-43331
- CVE-2025-43317
- CVE-2025-43340
- CVE-2025-43337
- CVE-2025-43320
- CVE-2025-43285
- CVE-2025-43330
- CVE-2025-43346
- CVE-2025-43361
- CVE-2025-43451
- CVE-2025-43307
- CVE-2025-43354
- CVE-2025-43303
- CVE-2025-43357
- CVE-2025-43323
- CVE-2025-43403
- CVE-2025-43349
- CVE-2025-43292
- CVE-2025-43372
- CVE-2025-24088
- CVE-2025-43305
- CVE-2025-43290
- CVE-2025-43289
- CVE-2025-46284
- CVE-2025-43316
- CVE-2025-31271
- CVE-2025-31270
- CVE-2025-43326
- CVE-2025-43283
- CVE-2025-46280
- CVE-2025-43325
- CVE-2025-43287
- CVE-2025-43338
- CVE-2025-43302
- CVE-2025-31255
- CVE-2025-43366
- CVE-2025-43359
- CVE-2025-43345
- CVE-2025-43299
- CVE-2025-43295
- CVE-2025-43353
- CVE-2025-43294
- CVE-2025-43319
- CVE-2025-43315
- CVE-2025-43355
- CVE-2025-43207
- CVE-2025-43279
- CVE-2025-43301
- CVE-2025-43298
- CVE-2025-46310
- CVE-2025-40909
- CVE-2025-43297
- CVE-2025-31269
- CVE-2025-43204
- CVE-2024-27280
- CVE-2025-46306
- CVE-2025-43327
- CVE-2025-43329
- CVE-2025-43328
- CVE-2025-43318
- CVE-2025-46307
- CVE-2025-31259
- CVE-2025-43332
- CVE-2025-43293
- CVE-2025-43291
- CVE-2025-43286
- CVE-2025-43369
- CVE-2025-43358
- CVE-2025-43367
- CVE-2025-43190
- CVE-2025-43333
- CVE-2025-24197
- CVE-2025-6965
- CVE-2025-43341
- CVE-2025-43314
- CVE-2025-43304
- CVE-2025-43306
- CVE-2025-43347
- CVE-2025-43296
- CVE-2025-43311
- CVE-2025-43308
- CVE-2025-43262
- CVE-2025-43356
- CVE-2025-43272
- CVE-2025-43343
- CVE-2025-43342
- CVE-2025-43419
- CVE-2025-43376
- CVE-2025-43368
- CVE-2025-43310
- CVE-2025-43464
- CVE-2025-43364
- CVE-2025-43508
Frequently Asked Questions
What is the severity of CVE-2025-46284?
The severity of CVE-2025-46284 is high, rated at 7 on the CVSS scale.
How do I fix CVE-2025-46284?
To fix CVE-2025-46284, update to macOS Sequoia 15.7 or macOS Tahoe 26.
What types of issues are associated with CVE-2025-46284?
CVE-2025-46284 is associated with race conditions, buffer overflow, and input validation issues.
What can happen if CVE-2025-46284 is exploited?
If exploited, CVE-2025-46284 may allow an application to gain root privileges.
What software versions are affected by CVE-2025-46284?
CVE-2025-46284 affects Apple macOS Sequoia and Apple macOS Tahoe.