CVE-2025-46301
Description
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. A malicious HID device may cause an unexpected process crash.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A malicious HID device can cause an unexpected process crash on Apple platforms due to insufficient bounds checks.
Root
Cause
CVE-2025-46301 is a vulnerability in Apple's HID (Human Interface Device) subsystem. The issue was addressed with improved bounds checks, and is caused by insufficient bounds checks when processing input from HID devices. This flaw can lead to memory corruption or an out-of-bounds access, resulting in an unexpected process crash [1][2][3][4].
Attack
Vector
An attacker with physical access to a device can connect a malicious HID device (e.g., a specially crafted keyboard, mouse, or other input device) to a vulnerable Apple device can trigger the crash. No user interaction beyond device connection is required; the vulnerability is triggered during normal HID processing [1][2][3][4].
Impact
Successful exploitation causes an unexpected process crash, leading to a denial of service (DoS). The crash may affect system stability or specific applications, depending on which process handles the malicious input. The CVSS v3 base score of 5.7 (Medium) reflects the requirement for physical access and the limited impact to availability [1][2][3][4].
Mitigation
Apple has released patches for a wide range of platforms: iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, and watchOS 26.2. Users should update their devices to the latest available versions to mitigate the risk [1][2][2][3][4].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
11cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*range: <18.7.5
- (no CPE)range: <18.7.5, <26.2
- Range: <26.2
- Range: <26.2
- Range: <26.2
- Range: <18.7.5, <26.2
- Range: <15.7.4
- Range: <14.8.4
- Range: <26.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- support.apple.com/en-us/126347nvdRelease NotesVendor Advisory
- support.apple.com/en-us/126349nvdRelease NotesVendor Advisory
- support.apple.com/en-us/126350nvdRelease NotesVendor Advisory
- support.apple.com/en-us/125884nvd
- support.apple.com/en-us/125886nvd
- support.apple.com/en-us/125889nvd
- support.apple.com/en-us/125890nvd
- support.apple.com/en-us/125891nvd
News mentions
0No linked articles in our index yet.