CVE-2025-31214
Published May 12, 2025
·Updated
AppleJPEG. The issue was addressed with improved input sanitization.
Credit
Hossein Lotfi@@hosselot(Trend Micro Zero Day Initiative), 秦若涵, 崔志伟, 崔宝江, Deval Jariwala, Guilherme Rambo(Best Buddy Apps), Dalibor Milanovic, Andrew James Gonzalez, YingQi Shi@@Mas0nShi(DBAppSecurity's WeBin lab), Duy Trần@@khanhduytran0, Dayton Pidhirney(Atredis Partners), Lyutoon, YenKoc, Saagar Jha, Tony Iskow@@Tybbow, Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), Lucas Leong@@_wmliang_(Trend Micro Zero Day Initiative), Christian Kohlschütter, CVE-2024-8176, Richard Hyunho Im@@richeeta, Paweł Płatek (Trail(Bits), Andr.Ess, Shehab Khan, wac, CertiK@@CertiK, Dave G., Eric Dorphy(Twin Cities App Dev LLC), Google V8 Security Team, Andreas Jaegersberger & Ro Achterberg(Nosebeard Labs), wac(Trend Micro Zero Day Initiative), rheza@@ginggilBesel(Palo Alto Networks), Edouard Bochin@@le_douds(Palo Alto Networks), Tao Yan@@Ga1ois(Palo Alto Networks), Nan Wang@@eternalsakura13, Ignacio Sanmillan@@ulexec, Jiming Wang, Jikai Ren, Yuhao Hu, Yan Kang, Chenggang Wu, Xiaojie Wei, Ivan Fratric(Google Project Zero), Juergen Schmied(Lynck GmbH), Thibaud Kehler, jioundai(360 Vulnerability Research Institute), chen fengjiao(HBC)
Affected Software
4 affected componentsFixes available
Apple iOS and iPadOS<18.5
18.5
Apple iOS, iPadOS, and macOS<18.5
18.5
Apple iOS, iPadOS, and macOS<18.5
iPhone OS<18.5
Event History
May 12, 2025
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
CVE Published
via MITRE·09:42 PM
Data Sourced
via MITRE·09:42 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-31214?
CVE-2025-31214 has been rated with high severity due to potential security risks associated with improper input handling.
2
How do I fix CVE-2025-31214?
To fix CVE-2025-31214, update your Apple iOS or iPadOS device to version 18.5 or later.
3
What products are affected by CVE-2025-31214?
CVE-2025-31214 affects Apple iOS and iPadOS versions below 18.5.
4
What type of vulnerability is CVE-2025-31214?
CVE-2025-31214 is characterized as an input sanitization vulnerability.
5
What was addressed in the CVE-2025-31214 update?
The update for CVE-2025-31214 addressed the issue with improved input sanitization and state management.