CVE-2025-31206: Double Free
A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Other sources
A type confusion issue was addressed with improved state handling. This issue is fixed in watchOS 11.5, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.
— Red Hat
afpfs. The issue was addressed with improved memory handling.
— Apple
afpfs. This issue was addressed with improved checks.
— Apple
AirDrop. A permissions issue was addressed with additional restrictions.
— Apple
Apple Intelligence Reports. A permissions issue was addressed with additional restrictions.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-24097
- CVE-2025-31251
- CVE-2025-31235
- CVE-2025-31208
- CVE-2025-31196
- CVE-2025-31209
- CVE-2025-31239
- CVE-2025-31233
- CVE-2025-24111
- CVE-2025-31210
- CVE-2025-30448
- CVE-2025-31226
- CVE-2025-24144
- CVE-2025-31219
- CVE-2025-31241
- CVE-2024-8176
- CVE-2025-24225
- CVE-2025-31228
- CVE-2025-24259
- CVE-2025-31245
- CVE-2025-24220
- CVE-2025-31221
- CVE-2025-31213
- CVE-2025-31242
- CVE-2025-31220
- CVE-2025-24213
- CVE-2025-31217
- CVE-2025-31215
- CVE-2025-31206
- CVE-2025-31212
- CVE-2025-31200
- CVE-2025-24224
- CVE-2025-31222
- CVE-2025-31223
- CVE-2025-31238
- CVE-2025-24223
- CVE-2025-31204
- CVE-2025-31205
- CVE-2025-31257
- CVE-2025-43374
- CVE-2025-31216
- CVE-2025-31214
- CVE-2025-31225
- CVE-2025-31253
- CVE-2025-31207
- CVE-2025-31227
- CVE-2025-31234
- CVE-2025-31266
- CVE-2025-31246
- CVE-2025-31240
- CVE-2025-31237
- CVE-2025-31260
- CVE-2025-24222
- CVE-2025-31236
- CVE-2025-30443
- CVE-2025-31232
- CVE-2025-30440
- CVE-2025-24274
- CVE-2025-31218
- CVE-2025-31256
- CVE-2025-24142
- CVE-2025-26465
- CVE-2025-26466
- CVE-2025-31244
- CVE-2025-31258
- CVE-2025-31249
- CVE-2025-31224
- CVE-2025-31247
- CVE-2025-31259
- CVE-2025-31250
- CVE-2025-31248
Frequently Asked Questions
What is the severity of CVE-2025-31206?
CVE-2025-31206 has been classified with a high severity due to its potential impact on user data and system functionality.
How do I fix CVE-2025-31206?
To fix CVE-2025-31206, update to the latest recommended versions for affected Apple software, including tvOS 18.5, macOS 15.5, iPadOS 17.7.7, and others.
What types of devices are affected by CVE-2025-31206?
CVE-2025-31206 affects various Apple devices, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS.
What vulnerabilities does CVE-2025-31206 address?
CVE-2025-31206 addresses memory handling issues and permissions vulnerabilities across multiple Apple platforms.
Is CVE-2025-31206 related to any specific applications?
CVE-2025-31206 is related to vulnerabilities found in Apple services including AirDrop and Apple Intelligence Reports.