CVE-2025-31209

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in watchOS 11.5, macOS Sonoma 14.7.6, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. Parsing a file may lead to disclosure of user information.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
appleCNA
---
---
CISA-ADPADP
6.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 12%
VendorProductVersion
appleipados
𝑥
< 17.7.7
appleipados
18.0 ≤
𝑥
< 18.5
appleiphone_os
𝑥
< 18.5
applemacos
𝑥
< 13.7.6
applemacos
14.0 ≤
𝑥
< 14.7.6
applemacos
15.0 ≤
𝑥
< 15.5
appletvos
𝑥
< 18.5
applevisionos
𝑥
< 2.5
applewatchos
𝑥
< 11.5
𝑥
= Vulnerable software versions