CVE-2025-31185: Input Validation
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3. Photos in the Hidden Photos Album may be viewed without authentication.
Other sources
Accessibility. An authentication issue was addressed with improved state management.
— Apple
AirPlay. A null pointer dereference was addressed with improved input validation.
— Apple
AirPlay. A type confusion issue was addressed with improved checks.
— Apple
AirPlay. An input validation issue was addressed.
— Apple
AirPlay. The issue was addressed with improved memory handling.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-24141
- CVE-2025-24126
- CVE-2025-24129
- CVE-2025-24131
- CVE-2025-24177
- CVE-2025-24179
- CVE-2025-24137
- CVE-2025-24127
- CVE-2025-24160
- CVE-2025-24161
- CVE-2025-24163
- CVE-2025-24123
- CVE-2025-24124
- CVE-2025-24085
- CVE-2025-24184
- CVE-2025-24111
- CVE-2025-24089
- CVE-2025-24090
- CVE-2025-24086
- CVE-2025-24144
- CVE-2025-24107
- CVE-2025-24159
- CVE-2025-24117
- CVE-2025-24091
- CVE-2024-55549
- CVE-2025-24855
- CVE-2025-24104
- CVE-2025-31262
- CVE-2024-9956
- CVE-2025-31185
- CVE-2025-24128
- CVE-2025-24113
- CVE-2025-24149
- CVE-2025-24145
- CVE-2025-24154
- CVE-2025-24189
- CVE-2025-24143
- CVE-2025-24158
- CVE-2025-24162
- CVE-2025-24150
Frequently Asked Questions
What is the severity of CVE-2025-31185?
CVE-2025-31185 is considered a high-severity vulnerability due to its potential impact on authentication and system stability.
How do I fix CVE-2025-31185?
To fix CVE-2025-31185, update your Apple iOS or iPadOS to version 18.3 or later.
What types of issues does CVE-2025-31185 address?
CVE-2025-31185 addresses authentication issues, null pointer dereferences, type confusion, and input validation problems.
Which products are affected by CVE-2025-31185?
CVE-2025-31185 affects Apple iOS and iPadOS versions prior to 18.3.
Is CVE-2025-31185 specific to AirPlay?
Yes, CVE-2025-31185 specifically involves vulnerabilities related to AirPlay functionalities.