First published: Mon May 12 2025(Updated: )
afpfs. The issue was addressed with improved memory handling.
Credit: Hossein Lotfi @hosselot Trend Micro Zero Day InitiativeGuilherme Rambo Best Buddy AppsApple Google Threat Analysis Group Saagar Jha Michael DePlante @izobashi Trend Micro Zero Day InitiativeLucas Leong @_wmliang_ Trend Micro Zero Day InitiativeChristian Kohlschütter CVE-2024-8176 Paweł Płatek (Trail BitsDave G. Google V8 Security Team Andreas Jaegersberger & Ro Achterberg Nosebeard Labswac Trend Micro Zero Day Initiativerheza @ginggilBesel an anonymous researcher Nan Wang @eternalsakura13 Ignacio Sanmillan @ulexec Jiming Wang Jikai Ren Ivan Fratric Google Project ZeroJuergen Schmied Lynck GmbHJoseph Ravichandran @0xjprx MIT CSAILThomas Völkl @vollkorntomate SEEMOO TU Darmstadt Dillon Franke Google Project ZeroKirin @Pwnrin Fudan UniversityLFY @secsys Fudan UniversityBohdan Stasiuk @bohdan_stasiuk Adam M. Sourabhkumar Mishra CVE-2025-26465 CVE-2025-26466 CertiK @CertiK wac Csaba Fitzl @theevilbit KandjiRyan Dowd @_rdowd Kirin @Pwnrin 7feilee Eric Dorphy Twin Cities App Dev LLCNoah Gregory (wts.dev) Dayton Pidhirney Atredis PartnersLyutoon YenKoc 秦若涵 崔志伟 崔宝江 Deval Jariwala Dalibor Milanovic Andrew James Gonzalez YingQi Shi @Mas0nShi DBAppSecurity's WeBin labDuy Trần @khanhduytran0 Richard Hyunho Im @richeeta Andr.Ess Shehab Khan
Affected Software | Affected Version | How to fix |
---|---|---|
macOS | <15.5 | 15.5 |
tvOS | <18.5 | 18.5 |
visionOS | <2.5 | 2.5 |
Apple iOS and iPadOS | <18.5 | 18.5 |
Apple iOS, iPadOS, and macOS | <18.5 | 18.5 |
Apple iOS, iPadOS, and watchOS | <11.5 | 11.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2025-31212 is classified as a high-severity vulnerability due to potential exploitation of memory handling and permissions issues.
To mitigate CVE-2025-31212, update your Apple devices to the latest versions of macOS Sequoia, tvOS, visionOS, iOS, iPadOS, or watchOS as specified in the advisory.
CVE-2025-31212 affects Apple macOS Sequoia, tvOS, visionOS, iOS, iPadOS, and watchOS up to specified versions.
CVE-2025-31212 addresses memory handling vulnerabilities and permissions issues with improved input checks.
CVE-2025-31212 was reported and addressed in 2025, highlighting ongoing improvements in security measures from Apple.