CVE-2025-31191

T

his issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.7.5, tvOS 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access sensitive user data.

Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*

History

03 Nov 2025, 22:18

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2025/Apr/10 -
  • () http://seclists.org/fulldisclosure/2025/Apr/11 -
  • () http://seclists.org/fulldisclosure/2025/Apr/4 -
  • () http://seclists.org/fulldisclosure/2025/Apr/8 -
  • () http://seclists.org/fulldisclosure/2025/Apr/9 -

03 Nov 2025, 20:18

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2025/Apr/13 -

10 May 2025, 17:15

Type Values Removed Values Added
References
  • () https://www.microsoft.com/en-us/security/blog/2025/05/01/analyzing-cve-2025-31191-a-macos-security-scoped-bookmarks-based-sandbox-escape/ -

04 Apr 2025, 18:14

Type Values Removed Values Added
References () https://support.apple.com/en-us/122371 - () https://support.apple.com/en-us/122371 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122373 - () https://support.apple.com/en-us/122373 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122374 - () https://support.apple.com/en-us/122374 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122375 - () https://support.apple.com/en-us/122375 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122377 - () https://support.apple.com/en-us/122377 - Release Notes, Vendor Advisory
Summary
  • (es) Este problema se solucionó mejorando la gestión del estado. Está corregido en macOS Ventura 13.7.5, tvOS 18.4, iOS 18.4 y iPadOS 18.4, macOS Sequoia 15.4 y macOS Sonoma 14.7.5. Una aplicación podría acceder a datos confidenciales del usuario.
CPE cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
First Time Apple macos
Apple tvos
Apple ipados
Apple iphone Os
Apple

01 Apr 2025, 05:15

Type Values Removed Values Added
CWE CWE-200
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

31 Mar 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-31 23:15

Updated : 2025-11-03 22:18


NVD link : CVE-2025-31191

Mitre link : CVE-2025-31191

CVE.ORG link : CVE-2025-31191


JSON object : View

Products Affected
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor