CVE-2025-46299

Overview

Advisory: Apple Security Advisory

Impact:

Description: Processing maliciously crafted web content may disclose internal states of the app

Researchers: Google Big Sleep

Attribute Value
CVE CVE-2025-46299
Bugzilla 299518
Component WebKit
Bug Class LogicError
Severity medium
Advisory Apple Advisory

Fix not public. The WebKit fix for this bug is embargoed or not yet disclosed. The bug ID is confirmed from the Apple advisory, but no public commit references it.

Root Cause Analysis

A memory initialization issue was addressed with improved memory handling.