CVE-2025-46311: Integer Overflow
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2. An app may be able to access sensitive user data.
Other sources
App Store. A permissions issue was addressed with additional restrictions.
— Apple
AppleJPEG. The issue was addressed with improved bounds checks.
— Apple
BiometricKit. A logic issue was addressed with improved validation.
— Apple
Books. A path handling issue was addressed with improved validation.
— Apple
Call History. An inconsistent user interface issue was addressed with improved state management.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-43539
- CVE-2025-46287
- CVE-2024-7264
- CVE-2025-9086
- CVE-2025-43542
- CVE-2025-43532
- CVE-2025-46279
- CVE-2025-43512
- CVE-2025-46285
- CVE-2025-5918
- CVE-2025-46311
- CVE-2025-46276
- CVE-2025-43538
- CVE-2025-46290
- CVE-2025-43530
- CVE-2025-46292
- CVE-2025-43535
- CVE-2025-43541
- CVE-2025-43501
- CVE-2025-43536
- CVE-2025-43531
- CVE-2025-14174
- CVE-2025-43529
- CVE-2025-46288
- CVE-2025-46286
- CVE-2025-43537
- CVE-2025-43518
- CVE-2025-43534
- CVE-2025-43475
- CVE-2025-43533
- CVE-2025-46300
- CVE-2025-46301
- CVE-2025-46302
- CVE-2025-46303
- CVE-2025-46304
- CVE-2025-46305
- CVE-2025-43428
- CVE-2025-46277
- CVE-2025-46298
- CVE-2025-46299
- CVE-2025-43511
Frequently Asked Questions
What is the severity of CVE-2025-46311?
The severity of CVE-2025-46311 is rated high with a CVSS score of 7.5.
How do I fix CVE-2025-46311?
To fix CVE-2025-46311, update to iOS version 18.7.3 or 26.2, or iPadOS version 18.7.3 or 26.2.
What type of issue is identified in CVE-2025-46311?
CVE-2025-46311 identifies an inconsistent user interface issue that may allow access to sensitive user data.
What software is affected by CVE-2025-46311?
CVE-2025-46311 affects Apple iOS and iPadOS on supported devices.
What improvements were made to address CVE-2025-46311?
CVE-2025-46311 was addressed with improved state management and additional restrictions on permissions.