CVE-2025-30470: Path Traversal
A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, visionOS 2.4, watchOS 11.4. An app may be able to read sensitive location information.
Other sources
Accessibility. A logging issue was addressed with improved data redaction.
— Apple
AccountPolicy. This issue was addressed by removing the vulnerable code.
— Apple
Accounts. This issue was addressed with improved data access restriction.
— Apple
AirDrop. A permissions issue was addressed with additional restrictions.
— Apple
AirPlay. A null pointer dereference was addressed with improved input validation.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-24234
- CVE-2025-24131
- CVE-2025-24270
- CVE-2025-24271
- CVE-2025-24177
- CVE-2025-24179
- CVE-2025-24251
- CVE-2025-31197
- CVE-2025-24252
- CVE-2025-30445
- CVE-2025-24129
- CVE-2025-24126
- CVE-2025-24206
- CVE-2025-24276
- CVE-2024-40864
- CVE-2025-24272
- CVE-2025-24231
- CVE-2025-24233
- CVE-2025-30443
- CVE-2025-43205
- CVE-2025-24243
- CVE-2025-24244
- CVE-2025-30460
- CVE-2025-24237
- CVE-2025-30429
- CVE-2025-24212
- CVE-2025-24215
- CVE-2025-24230
- CVE-2025-24085
- CVE-2025-24190
- CVE-2025-24211
- CVE-2025-31191
- CVE-2025-24170
- CVE-2025-24277
- CVE-2024-9681
- CVE-2025-31189
- CVE-2025-24255
- CVE-2025-24267
- CVE-2025-30456
- CVE-2025-24111
- CVE-2025-31187
- CVE-2025-30462
- CVE-2025-24199
- CVE-2025-30447
- CVE-2025-24256
- CVE-2025-24273
- CVE-2025-30464
- CVE-2025-24210
- CVE-2025-24249
- CVE-2025-24229
- CVE-2025-24235
- CVE-2025-30432
- CVE-2025-24203
- CVE-2025-24148
- CVE-2025-24195
- CVE-2025-27113
- CVE-2024-56171
- CVE-2025-24178
- CVE-2025-31182
- CVE-2025-24238
- CVE-2025-31264
- CVE-2025-24172
- CVE-2025-30450
- CVE-2025-30470
- CVE-2025-24232
- CVE-2025-24246
- CVE-2025-24261
- CVE-2025-24164
- CVE-2025-30446
- CVE-2025-24259
- CVE-2025-30424
- CVE-2025-24173
- CVE-2025-30452
- CVE-2025-24181
- CVE-2025-30471
- CVE-2025-24250
- CVE-2025-30438
- CVE-2025-31194
- CVE-2025-30465
- CVE-2025-30433
- CVE-2025-24139
- CVE-2025-24198
- CVE-2025-24205
- CVE-2025-30444
- CVE-2025-24228
- CVE-2025-24260
- CVE-2025-24254
- CVE-2024-54533
- CVE-2025-24207
- CVE-2025-31261
- CVE-2025-24253
- CVE-2025-30449
- CVE-2025-31188
- CVE-2025-24240
- CVE-2025-24278
- CVE-2025-30457
- CVE-2025-24279
- CVE-2025-24247
- CVE-2025-24241
- CVE-2025-24266
- CVE-2025-24265
- CVE-2025-24157
- CVE-2025-31198
- CVE-2025-24221
- CVE-2025-31202
- CVE-2025-30430
- CVE-2025-24180
- CVE-2025-24163
- CVE-2025-31196
- CVE-2025-24182
- CVE-2025-31203
- CVE-2025-30439
- CVE-2025-24283
- CVE-2025-24257
- CVE-2024-48958
- CVE-2025-24194
- CVE-2025-31199
- CVE-2025-30426
- CVE-2025-24095
- CVE-2025-30466
- CVE-2025-24113
- CVE-2025-24214
- CVE-2025-31184
- CVE-2025-24192
- CVE-2025-24264
- CVE-2025-24216
- CVE-2025-30427
- CVE-2025-24097
- CVE-2025-30454
- CVE-2025-30467
- CVE-2025-24167
- CVE-2025-31183
- CVE-2025-24217
- CVE-2025-24201
- CVE-2025-24209
- CVE-2025-30425
- CVE-2025-24202
- CVE-2025-30463
- CVE-2025-30434
- CVE-2025-24193
- CVE-2025-30428
- CVE-2025-30469
- CVE-2025-31192
- CVE-2025-24220
- CVE-2025-30436
- CVE-2025-24208
- CVE-2025-24239
- CVE-2025-31272
- CVE-2025-24245
- CVE-2025-24236
- CVE-2025-30453
- CVE-2025-24258
- CVE-2025-30455
- CVE-2025-30451
- CVE-2025-24281
- CVE-2025-30461
- CVE-2025-30431
- CVE-2025-30448
- CVE-2025-31263
- CVE-2025-30437
- CVE-2025-24204
- CVE-2025-24196
- CVE-2025-31231
- CVE-2025-46308
- CVE-2025-24262
- CVE-2023-27043
- CVE-2025-24284
- CVE-2025-30459
- CVE-2025-24191
- CVE-2025-24093
- CVE-2025-30458
- CVE-2025-24268
- CVE-2025-43184
- CVE-2025-24280
- CVE-2025-30435
- CVE-2025-24248
- CVE-2025-24269
- CVE-2025-24165
- CVE-2025-30442
- CVE-2025-24282
- CVE-2025-24263
- CVE-2025-46293
- CVE-2025-43278
- CVE-2025-24218
- CVE-2025-24242
- CVE-2025-31195
- CVE-2025-43465
- CVE-2025-24107
Frequently Asked Questions
What is the severity of CVE-2025-30470?
CVE-2025-30470 is a vulnerability that allows an app to potentially read sensitive location information.
How do I fix CVE-2025-30470?
To fix CVE-2025-30470, update your device to visionOS 2.4, macOS Ventura 13.7.5, iOS 18.4, iPadOS 18.4, macOS Sequoia 15.4, or macOS Sonoma 14.7.5.
Which devices are affected by CVE-2025-30470?
CVE-2025-30470 affects devices running specific versions of iPadOS, iOS, macOS Ventura, macOS Sequoia, macOS Sonoma, and visionOS.
Is CVE-2025-30470 a critical vulnerability?
CVE-2025-30470 allows for unauthorized access to location data, which can expose users to privacy risks.
What improvements were made in the fix for CVE-2025-30470?
The fix for CVE-2025-30470 includes improved logic to handle path management better.