CVE-2025-46287: Input Validation
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2. An attacker may be able to spoof their FaceTime caller ID.
Other sources
App Store. A permissions issue was addressed with additional restrictions.
— Apple
AppleJPEG. The issue was addressed with improved bounds checks.
— Apple
AppleMobileFileIntegrity. A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.
— Apple
AppleMobileFileIntegrity. A permissions issue was addressed with additional restrictions.
— Apple
AppleMobileFileIntegrity. The issue was addressed by adding additional logic.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-43539
- CVE-2025-43519
- CVE-2025-46289
- CVE-2025-43482
- CVE-2025-43517
- CVE-2025-46287
- CVE-2024-7264
- CVE-2025-9086
- CVE-2025-43518
- CVE-2025-43532
- CVE-2025-43512
- CVE-2025-46285
- CVE-2025-5918
- CVE-2025-43513
- CVE-2025-46276
- CVE-2025-43509
- CVE-2025-43538
- CVE-2025-43463
- CVE-2025-43416
- CVE-2025-43516
- CVE-2025-43530
- CVE-2025-43320
- CVE-2025-43522
- CVE-2025-43521
- CVE-2025-43523
- CVE-2025-43542
- CVE-2025-43527
- CVE-2025-46288
- CVE-2025-46279
- CVE-2025-43533
- CVE-2025-46300
- CVE-2025-46301
- CVE-2025-46302
- CVE-2025-46303
- CVE-2025-46304
- CVE-2025-46305
- CVE-2025-43428
- CVE-2025-46290
- CVE-2025-43541
- CVE-2025-43535
- CVE-2025-46298
- CVE-2025-43501
- CVE-2025-43531
- CVE-2025-14174
- CVE-2025-43529
- CVE-2025-46299
- CVE-2025-43511
- CVE-2025-46277
- CVE-2025-46311
- CVE-2025-46292
- CVE-2025-43536
- CVE-2025-46286
- CVE-2025-43537
- CVE-2025-43534
- CVE-2025-43475
- CVE-2025-46297
- CVE-2025-46283
- CVE-2025-46281
- CVE-2025-43417
- CVE-2025-46278
- CVE-2025-43524
- CVE-2025-46291
- CVE-2025-43410
- CVE-2025-43526
- CVE-2024-8906
- CVE-2025-43514
- CVE-2025-46282
Frequently Asked Questions
What is the severity of CVE-2025-46287?
The severity of CVE-2025-46287 is classified as high due to its potential to allow spoofing of FaceTime caller IDs.
How do I fix CVE-2025-46287?
To fix CVE-2025-46287, upgrade to macOS Sonoma 14.8.3 or macOS Sequoia 15.7.3.
Which products are affected by CVE-2025-46287?
CVE-2025-46287 affects Apple iOS, iPadOS, macOS Sonoma, macOS Sequoia, watchOS, and visionOS versions prior to their latest updates.
What is the nature of the issue in CVE-2025-46287?
CVE-2025-46287 involves an inconsistent user interface issue that could lead to caller ID spoofing in FaceTime.
Was this vulnerability fixed in any updates?
Yes, CVE-2025-46287 was addressed in updates for macOS Sonoma 14.8.3 and macOS Sequoia 15.7.3.