The issue was addressed with improved bounds checks. This issue is fixed in macOS Tahoe 26, Keynote 15.1, iOS 26 and iPadOS 26. Processing a maliciously crafted Keynote file may disclose memory contents.
History

Thu, 29 Jan 2026 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 29 Jan 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios
Apple ipad Os
Apple keynote
Apple macos
Apple macos Tahoe
Vendors & Products Apple
Apple ios
Apple ipad Os
Apple keynote
Apple macos
Apple macos Tahoe

Wed, 28 Jan 2026 17:45:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved bounds checks. This issue is fixed in macOS Tahoe 26, Keynote 15.1, iOS 26 and iPadOS 26. Processing a maliciously crafted Keynote file may disclose memory contents.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published: 2026-01-28T17:26:19.751Z

Updated: 2026-01-29T16:41:52.396Z

Reserved: 2025-04-22T21:13:49.960Z

Link: CVE-2025-46306

cve-icon Vulnrichment

Updated: 2026-01-29T16:04:39.151Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-28T18:16:49.213

Modified: 2026-01-29T17:16:19.760

Link: CVE-2025-46306

cve-icon Redhat

No data.