CVE-2025-46289: Medium severity Apple macOS Sonoma vulnerability
A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. An app may be able to access protected user data.
Other sources
App Store. A permissions issue was addressed with additional restrictions.
— Apple
AppleJPEG. The issue was addressed with improved bounds checks.
— Apple
AppleMobileFileIntegrity. A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.
— Apple
AppleMobileFileIntegrity. A permissions issue was addressed with additional restrictions.
— Apple
AppleMobileFileIntegrity. The issue was addressed by adding additional logic.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-43539
- CVE-2025-43519
- CVE-2025-46289
- CVE-2025-43482
- CVE-2025-43517
- CVE-2025-46287
- CVE-2024-7264
- CVE-2025-9086
- CVE-2025-43518
- CVE-2025-43532
- CVE-2025-43512
- CVE-2025-46285
- CVE-2025-5918
- CVE-2025-43513
- CVE-2025-46276
- CVE-2025-43509
- CVE-2025-43538
- CVE-2025-43463
- CVE-2025-43416
- CVE-2025-43516
- CVE-2025-43530
- CVE-2025-43320
- CVE-2025-43522
- CVE-2025-43521
- CVE-2025-43523
- CVE-2025-43542
- CVE-2025-43527
- CVE-2025-46288
- CVE-2025-46297
- CVE-2025-46283
- CVE-2025-46281
- CVE-2025-43417
- CVE-2025-46278
- CVE-2025-46279
- CVE-2025-43524
- CVE-2025-46291
- CVE-2025-43533
- CVE-2025-46300
- CVE-2025-46301
- CVE-2025-46302
- CVE-2025-46303
- CVE-2025-46304
- CVE-2025-46305
- CVE-2025-43410
- CVE-2025-43428
- CVE-2025-43526
- CVE-2024-8906
- CVE-2025-46277
- CVE-2025-46290
- CVE-2025-43514
- CVE-2025-46282
- CVE-2025-43541
- CVE-2025-43536
- CVE-2025-43535
- CVE-2025-46298
- CVE-2025-43501
- CVE-2025-43531
- CVE-2025-14174
- CVE-2025-43529
- CVE-2025-46299
- CVE-2025-43511
Frequently Asked Questions
What is the severity of CVE-2025-46289?
CVE-2025-46289 has been classified as a logic issue with the potential to expose protected user data.
How do I fix CVE-2025-46289?
To fix CVE-2025-46289, update your system to macOS Sonoma 14.8.3 or macOS Sequoia 15.7.3.
Which versions of macOS are affected by CVE-2025-46289?
CVE-2025-46289 affects macOS Tahoe versions below 26.2, macOS Sonoma versions below 14.8.3, and macOS Sequoia versions below 15.7.3.
What types of issues does CVE-2025-46289 address?
CVE-2025-46289 addresses permissions issues and improved file handling to prevent unauthorized access to protected user data.
Is my device at risk with CVE-2025-46289?
If you are using an affected version of macOS, your device may be at risk until you update to the latest version.