CVE-2025-46305
Description
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. A malicious HID device may cause an unexpected process crash.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A malicious HID device can cause an unexpected process crash on Apple platforms due to insufficient bounds checks.
Vulnerability
Overview
CVE-2025-46305 is a denial-of-service vulnerability in Apple's HID subsystem. The issue stems from insufficient bounds checks when processing input from HID devices. By sending specially crafted input, a malicious HID device can trigger an out-of-bounds memory access, leading to an unexpected process crash [1][2].
Attack
Vector and Prerequisites
Exploitation requires physical access to the device to connect a malicious HID device, such as a USB keyboard or other input device. No additional authentication or user interaction is needed beyond the physical connection. The attacker must be able to plug in a device that the system recognizes as a HID device [1][2].
Impact
A successful attack causes the targeted process to crash unexpectedly. While the crash itself does not directly lead to code execution or data theft, it can disrupt system operations and potentially be used to bypass security mechanisms that rely on the crashed process. The vulnerability affects a wide range of Apple platforms, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS [1][2][3][4].
Mitigation
Apple has addressed the issue with improved bounds checks in the following releases: iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, and watchOS 26.2. Users are strongly advised to update their devices to the latest available versions [1][2][3][4].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
6cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*range: >=14.0,<14.8.4
- (no CPE)range: <15.7.4
- Range: <26.2
- Range: <18.7.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- support.apple.com/en-us/126347nvdRelease NotesVendor Advisory
- support.apple.com/en-us/126349nvdRelease NotesVendor Advisory
- support.apple.com/en-us/126350nvdRelease NotesVendor Advisory
- support.apple.com/en-us/125884nvd
- support.apple.com/en-us/125886nvd
- support.apple.com/en-us/125889nvd
- support.apple.com/en-us/125890nvd
- support.apple.com/en-us/125891nvd
News mentions
0No linked articles in our index yet.