CVE-2025-31221

A

n integer overflow was addressed with improved input validation. This issue is fixed in watchOS 11.5, macOS Sonoma 14.7.6, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. A remote attacker may be able to leak memory.

Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

History

03 Nov 2025, 20:18

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2025/May/10 -
  • () http://seclists.org/fulldisclosure/2025/May/12 -
  • () http://seclists.org/fulldisclosure/2025/May/5 -
  • () http://seclists.org/fulldisclosure/2025/May/6 -
  • () http://seclists.org/fulldisclosure/2025/May/7 -
  • () http://seclists.org/fulldisclosure/2025/May/8 -
  • () http://seclists.org/fulldisclosure/2025/May/9 -

27 May 2025, 21:28

Type Values Removed Values Added
First Time Apple watchos
Apple iphone Os
Apple
Apple ipados
Apple tvos
Apple macos
Apple visionos
References () https://support.apple.com/en-us/122404 - () https://support.apple.com/en-us/122404 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122405 - () https://support.apple.com/en-us/122405 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122716 - () https://support.apple.com/en-us/122716 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122717 - () https://support.apple.com/en-us/122717 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122718 - () https://support.apple.com/en-us/122718 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122720 - () https://support.apple.com/en-us/122720 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122721 - () https://support.apple.com/en-us/122721 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122722 - () https://support.apple.com/en-us/122722 - Release Notes, Vendor Advisory
CPE cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*

14 May 2025, 16:15

Type Values Removed Values Added
CWE CWE-284 CWE-190

13 May 2025, 20:15

Type Values Removed Values Added
CWE CWE-284
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

13 May 2025, 19:35

Type Values Removed Values Added
Summary
  • (es) Se solucionó un desbordamiento de enteros mejorando la validación de entrada. Este problema se solucionó en watchOS 11.5, macOS Sonoma 14.7.6, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 y iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5 y macOS Ventura 13.7.6. Un atacante remoto podría tener la capacidad de filtrar memoria.

12 May 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-12 22:15

Updated : 2025-11-03 20:18


NVD link : CVE-2025-31221

Mitre link : CVE-2025-31221

CVE.ORG link : CVE-2025-31221


JSON object : View

CWE
CWE-190

Integer Overflow or Wraparound