CVE-2025-46311: An app may be able to access sensitive user data in Apple iOS and iPadOS
CVE-2025-46311 is a high-severity vulnerability in Apple iOS and iPadOS where an inconsistent user interface issue could allow an app to access sensitive user data. The issue was addressed by Apple through improved state management and fixed in iOS 18.7.3, iPadOS 18.7.3, iOS 26.2, and iPadOS 26.2. The vulnerability has a CVSS score of 7.5, indicating a significant impact on confidentiality without requiring user interaction or privileges.
AI Analysis
Technical Summary
This vulnerability involves an inconsistent user interface state management flaw in Apple iOS and iPadOS that could permit an app to access sensitive user data improperly. Apple fixed the issue in versions iOS 18.7.3, iPadOS 18.7.3, iOS 26.2, and iPadOS 26.2 by improving state management to prevent unauthorized data access. The CVSS 3.1 base score is 7.5 with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, indicating network attack vector, low attack complexity, no privileges or user interaction required, unchanged scope, and high confidentiality impact. No official remediation level or patch links were provided in the source data, but the vendor advisory states the issue is fixed in the specified versions.
Potential Impact
An attacker could exploit this vulnerability remotely without any privileges or user interaction to access sensitive user data on affected iOS and iPadOS devices. The confidentiality impact is high, but integrity and availability are not affected. There are no known exploits in the wild currently.
Mitigation Recommendations
Apple has fixed this vulnerability in iOS 18.7.3, iPadOS 18.7.3, iOS 26.2, and iPadOS 26.2. Users and administrators should update affected devices to these or later versions to remediate the issue. Patch status is confirmed by the vendor advisory indicating the fix is available in these versions.
CVE-2025-46311: An app may be able to access sensitive user data in Apple iOS and iPadOS
Description
CVE-2025-46311 is a high-severity vulnerability in Apple iOS and iPadOS where an inconsistent user interface issue could allow an app to access sensitive user data. The issue was addressed by Apple through improved state management and fixed in iOS 18.7.3, iPadOS 18.7.3, iOS 26.2, and iPadOS 26.2. The vulnerability has a CVSS score of 7.5, indicating a significant impact on confidentiality without requiring user interaction or privileges.
CVSS v3.1
Score 7.5high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves an inconsistent user interface state management flaw in Apple iOS and iPadOS that could permit an app to access sensitive user data improperly. Apple fixed the issue in versions iOS 18.7.3, iPadOS 18.7.3, iOS 26.2, and iPadOS 26.2 by improving state management to prevent unauthorized data access. The CVSS 3.1 base score is 7.5 with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, indicating network attack vector, low attack complexity, no privileges or user interaction required, unchanged scope, and high confidentiality impact. No official remediation level or patch links were provided in the source data, but the vendor advisory states the issue is fixed in the specified versions.
Potential Impact
An attacker could exploit this vulnerability remotely without any privileges or user interaction to access sensitive user data on affected iOS and iPadOS devices. The confidentiality impact is high, but integrity and availability are not affected. There are no known exploits in the wild currently.
Mitigation Recommendations
Apple has fixed this vulnerability in iOS 18.7.3, iPadOS 18.7.3, iOS 26.2, and iPadOS 26.2. Users and administrators should update affected devices to these or later versions to remediate the issue. Patch status is confirmed by the vendor advisory indicating the fix is available in these versions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apple
- Date Reserved
- 2025-04-22T21:13:49.961Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a036fc8cbff5d86100cc440
Added to database: 05/12/2026, 18:22:00 UTC
Last enriched: 05/19/2026, 19:06:42 UTC
Last updated: 07/31/2026, 19:22:55 UTC
Views: 101
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.