First published: Mon May 12 2025(Updated: )
afpfs. The issue was addressed with improved memory handling.
Credit: Joseph Ravichandran @0xjprx MIT CSAILDave G. Hossein Lotfi @hosselot Trend Micro Zero Day InitiativeDillon Franke Google Project Zerowac Trend Micro Zero Day InitiativeCsaba Fitzl @theevilbit Kandjian anonymous researcher Lyutoon Atredis PartnersYenKoc Atredis PartnersDayton Pidhirney Atredis PartnersMateusz Krzywicki @krzywix Michael DePlante @izobashi Trend Micro Zero Day InitiativeLucas Leong @_wmliang_ Trend Micro Zero Day InitiativeChristian Kohlschütter CVE-2024-8176 Paweł Płatek (Trail BitsLFY @secsys Fudan UniversityCVE-2025-26465 CVE-2025-26466 wac Kirin @Pwnrin 7feilee Eric Dorphy Twin Cities App Dev LLCAdam M. Ron Masas BREAKPOINTWang Yu CyberservalAndrew James Gonzalez Saagar Jha Richard Hyunho Im @richeeta Andr.Ess Noah Gregory (wts.dev) Wojciech Regula SecuRingGoogle V8 Security Team Ignacio Sanmillan @ulexec Jiming Wang Jikai Ren Thomas Völkl @vollkorntomate SEEMOO TU Darmstadt Guilherme Rambo Best Buddy AppsKirin @Pwnrin Fudan UniversityBohdan Stasiuk @bohdan_stasiuk Sourabhkumar Mishra CertiK @CertiK Ryan Dowd @_rdowd Andreas Jaegersberger & Ro Achterberg Nosebeard LabsNan Wang @eternalsakura13 rheza @ginggilBesel Ivan Fratric Google Project ZeroJuergen Schmied Lynck GmbHLyutoon YenKoc
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS | <14.7.6 | 14.7.6 |
Apple iOS, iPadOS, and macOS | <17.7.7 | 17.7.7 |
macOS | <15.5 | 15.5 |
macOS Ventura | <13.7.6 | 13.7.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
The severity of CVE-2025-31235 is critical due to memory handling issues that could allow arbitrary code execution.
To fix CVE-2025-31235, update your system to the latest version of macOS or iPadOS as specified by Apple.
CVE-2025-31235 affects macOS Sonoma, macOS Ventura, macOS Sequoia, and iPadOS.
CVE-2025-31235 addresses issues related to memory handling and permissions that could potentially be exploited.
The vendor of the affected software is Apple.