VYPR
Medium severity5.3NVD Advisory· Published Jun 11, 2026· Updated Jun 11, 2026

CVE-2025-46308

CVE-2025-46308

Description

An authorization issue in Apple iOS/iPadOS and macOS allows an app to leak sensitive user data; fixed in iOS 18.4, iPadOS 18.4, and macOS Sequoia 15.4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An authorization issue in Apple iOS/iPadOS and macOS allows an app to leak sensitive user data; fixed in iOS 18.4, iPadOS 18.4, and macOS Sequoia 15.4.

Vulnerability

An authorization issue in the state management of iOS, iPadOS, and macOS allows an app to access sensitive user data that should be protected. This issue is present in versions prior to iOS 18.4, iPadOS 18.4, and macOS Sequoia 15.4. The underlying problem is a logging issue where sensitive data is not properly redacted, as described in the security advisories [1][2].

Exploitation

An attacker would need to have an app installed on the device. No special privileges or user interaction beyond normal app usage are required. The app can exploit the authorization flaw to access sensitive data that is improperly logged or exposed due to state management issues.

Impact

Successful exploitation allows the app to leak sensitive user information, such as personal data. The impact is information disclosure, potentially compromising user privacy.

Mitigation

Apple fixed the issue in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, released March 31, 2025. Users should update to these versions. No workarounds are mentioned in the available references [1][2].

AI Insight generated on Jun 11, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.