CVE-2025-46299: Integer Overflow
A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may disclose internal states of the app.
Other sources
A memory initialization issue was addressed with improved memory handling. This issue is fixed in tvOS 26.2, Safari 26.2, watchOS 26.2, visionOS 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2. Processing maliciously crafted web content may disclose internal states of the app.
— Red Hat
App Store. A permissions issue was addressed with additional restrictions.
— Apple
AppleJPEG. The issue was addressed with improved bounds checks.
— Apple
AppleMobileFileIntegrity. A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.
— Apple
AppleMobileFileIntegrity. A permissions issue was addressed with additional restrictions.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-43526
- CVE-2024-8906
- CVE-2025-46282
- CVE-2025-43541
- CVE-2025-43536
- CVE-2025-43535
- CVE-2025-46298
- CVE-2025-43501
- CVE-2025-43531
- CVE-2025-14174
- CVE-2025-43529
- CVE-2025-46299
- CVE-2025-43511
- CVE-2025-43539
- CVE-2024-7264
- CVE-2025-9086
- CVE-2025-43532
- CVE-2025-46279
- CVE-2025-46285
- CVE-2025-43533
- CVE-2025-46300
- CVE-2025-46301
- CVE-2025-46302
- CVE-2025-46303
- CVE-2025-46304
- CVE-2025-46305
- CVE-2025-46288
- CVE-2025-46287
- CVE-2025-43542
- CVE-2025-46276
- CVE-2025-43428
- CVE-2025-43538
- CVE-2025-46290
- CVE-2025-43518
- CVE-2025-46277
- CVE-2025-46286
- CVE-2025-43537
- CVE-2025-43534
- CVE-2025-5918
- CVE-2025-46311
- CVE-2025-43475
- CVE-2025-46292
- CVE-2025-43523
- CVE-2025-43519
- CVE-2025-43522
- CVE-2025-43521
- CVE-2025-46289
- CVE-2025-46297
- CVE-2025-43482
- CVE-2025-43517
- CVE-2025-46283
- CVE-2025-46281
- CVE-2025-43417
- CVE-2025-46278
- CVE-2025-43524
- CVE-2025-43512
- CVE-2025-46291
- CVE-2025-43513
- CVE-2025-43509
- CVE-2025-43410
- CVE-2025-43514
- CVE-2025-43527
- CVE-2025-43416
- CVE-2025-43516
- CVE-2025-43530
Frequently Asked Questions
What is the severity of CVE-2025-46299?
CVE-2025-46299 has been classified as a medium severity vulnerability that can disclose internal states of the app.
How do I fix CVE-2025-46299?
To fix CVE-2025-46299, ensure you update to the latest versions: tvOS 26.2, Safari 26.2, watchOS 26.2, visionOS 26.2, iOS 26.2, iPadOS 26.2, or macOS Tahoe 26.2.
What software is affected by CVE-2025-46299?
CVE-2025-46299 affects Apple tvOS, Safari, watchOS, visionOS, iOS, iPadOS, and macOS Tahoe versions prior to 26.2.
What types of attacks can CVE-2025-46299 facilitate?
CVE-2025-46299 can facilitate attacks aimed at processing maliciously crafted web content, potentially leading to unauthorized information disclosure.
When was CVE-2025-46299 disclosed?
CVE-2025-46299 was disclosed as part of a security update that included improvements to memory handling.