CVE-2025-31213: Double Free
A logging issue was addressed with improved data redaction. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be able to access associated usernames and websites in a user's iCloud Keychain.
Other sources
afpfs. The issue was addressed with improved memory handling.
— Apple
afpfs. This issue was addressed with improved checks.
— Apple
AirDrop. A permissions issue was addressed with additional restrictions.
— Apple
Apple Intelligence Reports. A permissions issue was addressed with additional restrictions.
— Apple
AppleJPEG. The issue was addressed with improved input sanitization.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-31240
- CVE-2025-31237
- CVE-2025-31251
- CVE-2025-31235
- CVE-2025-31208
- CVE-2025-31196
- CVE-2025-31209
- CVE-2025-31239
- CVE-2025-31233
- CVE-2025-30453
- CVE-2025-24258
- CVE-2025-30448
- CVE-2025-31232
- CVE-2025-24144
- CVE-2025-31219
- CVE-2025-31241
- CVE-2024-8176
- CVE-2025-30440
- CVE-2025-31222
- CVE-2025-24274
- CVE-2025-24142
- CVE-2025-31245
- CVE-2025-31224
- CVE-2025-31221
- CVE-2025-31213
- CVE-2025-31247
- CVE-2025-30442
- CVE-2025-31242
- CVE-2025-31220
- CVE-2025-24155
- CVE-2025-31246
- CVE-2025-26465
- CVE-2025-26466
- CVE-2025-24097
- CVE-2025-24111
- CVE-2025-31210
- CVE-2025-31226
- CVE-2025-24225
- CVE-2025-31228
- CVE-2025-24259
- CVE-2025-24220
- CVE-2025-24213
- CVE-2025-31217
- CVE-2025-31215
- CVE-2025-31206
- CVE-2025-31216
- CVE-2025-43374
- CVE-2025-31260
- CVE-2025-24222
- CVE-2025-31212
- CVE-2025-31236
- CVE-2025-30443
- CVE-2025-24224
- CVE-2025-31218
- CVE-2025-31256
- CVE-2025-31234
- CVE-2025-31244
- CVE-2025-31258
- CVE-2025-31266
- CVE-2025-31249
- CVE-2025-31259
- CVE-2025-31250
- CVE-2025-31248
- CVE-2025-31223
- CVE-2025-31238
- CVE-2025-31204
- CVE-2025-24223
- CVE-2025-31205
- CVE-2025-31257
Frequently Asked Questions
What is the severity of CVE-2025-31213?
CVE-2025-31213 has been classified as a high severity vulnerability due to its potential to exploit memory handling and permission issues.
How do I fix CVE-2025-31213?
To fix CVE-2025-31213, users should update their affected Apple macOS versions to the latest recommended releases.
Which Apple products are affected by CVE-2025-31213?
CVE-2025-31213 affects macOS Ventura up to version 13.7.6, macOS Sequoia up to version 15.5, and certain versions of iPadOS and macOS Sonoma.
What types of issues does CVE-2025-31213 involve?
CVE-2025-31213 involves improved memory handling, checks, and permission restrictions in various Apple software components.
Is there a workaround for CVE-2025-31213?
There is no official workaround for CVE-2025-31213; the best approach is to apply the necessary updates as soon as possible.