CVE-2025-46316

Severity
4.3MEDIUM
EPSS
0.0%
top 96.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 28

Description

An out-of-bounds read was addressed with improved input validation. This issue is fixed in Pages 15.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. Processing a maliciously crafted Pages document may result in unexpected termination or disclosure of process memory.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:LExploitability: 2.8 | Impact: 1.4

Affected Packages7 packages

CVEListV5apple/pages< 15.1
NVDapple/pages< 15.1
CVEListV5apple/macos< 26.1
NVDapple/macos< 26.1
NVDapple/ipados< 26.1

🔴Vulnerability Details

2
GHSA
GHSA-jrq9-fh3p-h9g6: An out-of-bounds read was addressed with improved input validation2026-01-28
CVEList
CVE-2025-46316: An out-of-bounds read was addressed with improved input validation2026-01-28

📋Vendor Advisories

4
Apple
CVE-2025-46316: Pages 15.12026-01-28
Apple
CVE-2025-46316: macOS Tahoe 26.12025-11-03
Apple
CVE-2025-46316: iOS 26.1 and iPadOS 26.12025-11-03
Microsoft
In buc Traceroute 2.0.12 through 2.1.2 before 2.1.3 the wrapper scripts do not properly parse command lines.2023-10-10

🕵️Threat Intelligence

1
Wiz
CVE-2025-46316 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2025-46316 (MEDIUM CVSS 4.3) | An out-of-bounds read was addressed | cvebase.io