CNNVD-202601-1587 Information

CNNVD ID

CNNVD-202601-1587

CVE-2025-46299

  • CNNVD Published: 2026-01-09

Description (Chinese)

Apple Safari等都是美国苹果(Apple)公司的产品。Apple Safari是一款Web浏览器,是Mac OS X和iOS操作系统附带的默认浏览器。Apple iOS是一套为移动设备所开发的操作系统。Apple tvOS是一套智能电视操作系统。 Apple多款产品存在安全漏洞,该漏洞源于内存初始化问题,可能导致处理恶意Web内容时泄露应用内部状态。以下产品及版本受到影响:tvOS 26.2之前版本、Safari 26.2之前版本、watchOS 26.2之前版本、visionOS 26.2之前版本、iOS 26.2之前版本和iPadOS 26.2之前版本、macOS Tahoe 26.2之前版本。

Description (English)

Apple Safari and others are the products of Apple. Apple Safari is a Web browser, a default browser attached to Mac OS X and iOS operating systems. Apple iOS is an operating system developed for mobile devices. Apple tvOS is a smart television operating system. There is a safety loophole in Apple’s multiple products, which stems from the problem of memory initialization and may lead to the disclosure of the internal state of application when dealing with malicious Web content. The following products and versions were affected: pre-tvOS 26.2; pre-Safari 26.2; pre-watch OS 26.2; pre-vision OS 26.2; pre-iOS 26.2 and pre-iPados 26.2; and pre-macOS Tahoe 26.2.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

苹果

Published

2026-01-09

Last Modified

2026-02-24

References

https://support.apple.com/en-us/125884 https://support.apple.com/en-us/125886 https://support.apple.com/en-us/125891 https://support.apple.com/en-us/125892 https://support.apple.com/en-us/125890 https://support.apple.com/en-us/125889 https://access.redhat.com/security/cve/cve-2025-46299

Patch

https://support.apple.com/en-us/125884

Share on: