CVE-2025-31281
CRITICAL | Platform: iOS | Changelog
CVE Details
Description
An input validation issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6. Processing a maliciously crafted file may lead to unexpected app termination.
CVSS 3.1 Score
| Metric | Value |
|---|---|
| Base Score | 9.1 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
Weakness
References
- Apple Security Advisory
- NVD Entry
- https://support.apple.com/en-us/124149 (Release Notes, Vendor Advisory)
- https://support.apple.com/en-us/124153 (Release Notes, Vendor Advisory)
- https://support.apple.com/en-us/124154 (Release Notes, Vendor Advisory)
- http://seclists.org/fulldisclosure/2025/Jul/30
- http://seclists.org/fulldisclosure/2025/Jul/32
- http://seclists.org/fulldisclosure/2025/Jul/36
- http://seclists.org/fulldisclosure/2025/Jul/37