CVE-2025-46299

Severity
4.3MEDIUM
EPSS
0.0%
top 93.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 9
Latest updateMar 19

Description

A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may disclose internal states of the app.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages14 packages

CVEListV5apple/tvos< 26.2
NVDapple/tvos< 26.2
CVEListV5apple/macos< 26.2
NVDapple/macos< 26.2
CVEListV5apple/safari< 26.2

🔴Vulnerability Details

4
GHSA
GHSA-29gc-r2qh-wc5v: A memory initialization issue was addressed with improved memory handling2026-01-10
OSV
CVE-2025-46299: A memory initialization issue was addressed with improved memory handling2026-01-09
OSV
CVE-2025-46299: A memory initialization issue was addressed with improved memory handling2026-01-09
CVEList
CVE-2025-46299: A memory initialization issue was addressed with improved memory handling2026-01-09

📋Vendor Advisories

8
Red Hat
webkitgtk: Processing maliciously crafted web content may disclose internal states of the app2026-03-18
Apple
CVE-2025-46299: macOS Tahoe 26.22025-12-12
Apple
CVE-2025-46299: visionOS 26.22025-12-12
Apple
CVE-2025-46299: watchOS 26.22025-12-12
Apple
CVE-2025-46299: tvOS 26.22025-12-12

🕵️Threat Intelligence

1
Wiz
CVE-2025-46299 Impact, Exploitability, and Mitigation Steps | Wiz

💬Community

1
Bugzilla
CVE-2025-46299 webkitgtk: Processing maliciously crafted web content may disclose internal states of the app [fedora-all]2026-03-19
CVE-2025-46299 (MEDIUM CVSS 4.3) | A memory initialization issue was a | cvebase.io