CVE-2025-46292 Details
Description
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2. An app may be able to access user-sensitive data.
A vulnerability exists in the Telephony framework of Apple iOS and iPadOS, specifically in versions 18.7.3 and 26.2. This vulnerability allows apps to access user-sensitive data due to insufficient entitlement checks. The issue has been addressed in the same versions where it was found.
Users can update to iOS 26.2 or iPadOS 26.2. For those on iOS 18.7.3 or iPadOS 18.7.3, the update is also available.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.apple.com/en-us/125884 | [email protected] | Release NotesVendor Advisory |
| https://support.apple.com/en-us/125885 | [email protected] | Release NotesVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-284 | Improper Access Control | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| apple ipados | < 18.7.3 >= 26.0, < 26.2 |
CPE
Remediation
| |
| apple iphone os | < 18.7.3 >= 26.0, < 26.2 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 2, 2026 | CVE Modified | [email protected] |
| Dec 18, 2025 | CVE Modified | CISA-ADP |
| Dec 18, 2025 | Initial Analysis | [email protected] |
| Dec 17, 2025 | New CVE Received | [email protected] |