Description A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2. An app may be able to access sensitive payment tokens.
CVSS vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Exploitability: 1.8 | Impact: 3.6 Attack Vector: Local
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: None
Availability: None
Affected Packages9 packages Show 4 more packages
🔴 Vulnerability Details2 CVEList CVE-2025-46288: A permissions issue was addressed with additional restrictions ↗ 2025-12-17 ▶ GHSA GHSA-mj63-pjmq-484f: A permissions issue was addressed with additional restrictions ↗ 2025-12-17 ▶
📋 Vendor Advisories4 Apple CVE-2025-46288: macOS Tahoe 26.2 ↗ 2025-12-12 ▶ Apple CVE-2025-46288: watchOS 26.2 ↗ 2025-12-12 ▶ Apple CVE-2025-46288: visionOS 26.2 ↗ 2025-12-12 ▶ Apple CVE-2025-46288: iOS 26.2 and iPadOS 26.2 ↗ 2025-12-12 ▶
🕵️ Threat Intelligence1 Wiz CVE-2025-46288 Impact, Exploitability, and Mitigation Steps | Wiz ↗ ▶