VYPR
Medium severity5.7NVD Advisory· Published Feb 11, 2026· Updated Apr 2, 2026

CVE-2025-46302

CVE-2025-46302

Description

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. A malicious HID device may cause an unexpected process crash.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CVE-2025-46302: A malicious Human Interface Device (HID) may trigger an unexpected process crash on Apple devices via an unaddressed bounds check.

Overview

CVE-2025-46302 is a vulnerability in Apple operating systems that allows a malicious Human Interface Device (HID) to cause an unexpected process crash. The issue was addressed with improved bounds checks, indicating an out-of-bounds condition in HID input handling that can lead to a denial-of-service scenario.

Exploitation

To exploit this vulnerability, an attacker requires physical access to the device to connect a malicious HID peripheral (e.g., a keyboard or other input device). No authentication or user interaction is needed beyond plugging in the device. The HID driver's lack of rigorous bounds checking on incoming data allows the attacker to trigger memory corruption that crashes the targeted process.

Impact

Successful exploitation results in an unexpected process crash, leading to denial of service. While the crash may temporarily disrupt the device's operation, there is no indication in the available references that code execution or privilege escalation is possible. The impact is limited to availability.

Mitigation

Apple has addressed this vulnerability in a wide range of product versions: iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, and watchOS 26.2 [1][2][3][4]. Users are advised to update to the latest available versions for their devices.

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

5

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.