First published: Mon May 12 2025(Updated: )
AirDrop. A permissions issue was addressed with additional restrictions.
Credit: Christian Kohlschütter CVE-2024-8176 Richard Hyunho Im @richeeta Andr.Ess Noah Gregory (wts.dev) wac Wojciech Regula SecuRingDave G. Kirin @Pwnrin 7feilee Eric Dorphy Twin Cities App Dev LLCAdam M. Google V8 Security Team Ignacio Sanmillan @ulexec Jiming Wang Jikai Ren an anonymous researcher Ron Masas BREAKPOINTHossein Lotfi @hosselot Trend Micro Zero Day InitiativeDillon Franke Google Project Zerowac Trend Micro Zero Day InitiativeWang Yu CyberservalAndrew James Gonzalez Lyutoon Atredis PartnersYenKoc Atredis PartnersDayton Pidhirney Atredis PartnersSaagar Jha Mateusz Krzywicki @krzywix Michael DePlante @izobashi Trend Micro Zero Day InitiativeLucas Leong @_wmliang_ Trend Micro Zero Day InitiativeDalibor Milanovic YingQi Shi @Mas0nShi DBAppSecurity's WeBin labDuy Trần @khanhduytran0 Lyutoon YenKoc Paweł Płatek (Trail BitsShehab Khan CertiK @CertiK Andreas Jaegersberger & Ro Achterberg Nosebeard Labsrheza @ginggilBesel Nan Wang @eternalsakura13 Ivan Fratric Google Project ZeroJuergen Schmied Lynck GmbH秦若涵 崔志伟 崔宝江 Deval Jariwala Guilherme Rambo Best Buddy Apps
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS, iPadOS, and macOS | <17.7.7 | 17.7.7 |
Apple iOS and iPadOS | <18.5 | 18.5 |
Apple iOS, iPadOS, and macOS | <18.5 | 18.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2025-31228 has not been explicitly stated, but it addresses multiple vulnerabilities that could impact system security.
To fix CVE-2025-31228, update your iPhone or iPad to iOS version 18.5 or iPadOS version 17.7.7 as applicable.
CVE-2025-31228 addresses issues related to permissions, input sanitization, memory management, and state management.
CVE-2025-31228 affects various versions of Apple iOS and iPadOS, specifically versions 17.7.7 and 18.5.
There are no specific mitigations mentioned for CVE-2025-31228 apart from updating to the latest software version.