VYPR
Medium severity5.7NVD Advisory· Published Feb 11, 2026· Updated Apr 2, 2026

CVE-2025-46300

CVE-2025-46300

Description

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. A malicious HID device may cause an unexpected process crash.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A malicious Human Interface Device (HID) may cause an unexpected process crash due to insufficient bounds checks in Apple operating systems.

Vulnerability

Details CVE-2025-46300 is a bounds checking flaw in the handling of HID input. Apple addressed the issue with improved bounds checks across multiple operating systems, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. [1][2][3][4]

Exploitation

Exploitation requires physical access to the device via a malicious HID peripheral. No authentication or user interaction beyond connecting the device is described.

Impact

A successful exploit can cause an unexpected process crash, leading to a denial of service. The description does not indicate code execution or privilege escalation.

Mitigation

Apple has released patches in iOS 18.7.5, iPadOS 18.7.5, iOS 26.2, iPadOS 26.2, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, and watchOS 26.2. Users should update their devices. [1][2][3][4]

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

6

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.