CVE-2025-31221: Input Validation
afpfs. The issue was addressed with improved memory handling.
Other sources
afpfs. This issue was addressed with improved checks.
— Apple
AirDrop. A permissions issue was addressed with additional restrictions.
— Apple
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. A remote attacker may be able to leak memory.
— MITRE
Apple Intelligence Reports. A permissions issue was addressed with additional restrictions.
— Apple
AppleJPEG. The issue was addressed with improved input sanitization.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-31240
- CVE-2025-31237
- CVE-2025-31251
- CVE-2025-31235
- CVE-2025-31208
- CVE-2025-31196
- CVE-2025-31209
- CVE-2025-31239
- CVE-2025-31233
- CVE-2025-30453
- CVE-2025-24258
- CVE-2025-30448
- CVE-2025-31232
- CVE-2025-24144
- CVE-2025-31219
- CVE-2025-31241
- CVE-2024-8176
- CVE-2025-30440
- CVE-2025-31222
- CVE-2025-24274
- CVE-2025-24142
- CVE-2025-31245
- CVE-2025-31224
- CVE-2025-31221
- CVE-2025-31213
- CVE-2025-31247
- CVE-2025-30442
- CVE-2025-31242
- CVE-2025-31220
- CVE-2025-24155
- CVE-2025-31246
- CVE-2025-26465
- CVE-2025-26466
- CVE-2025-24097
- CVE-2025-24111
- CVE-2025-31210
- CVE-2025-31226
- CVE-2025-24225
- CVE-2025-31228
- CVE-2025-24259
- CVE-2025-24220
- CVE-2025-24213
- CVE-2025-31217
- CVE-2025-31215
- CVE-2025-31206
- CVE-2025-31212
- CVE-2025-31200
- CVE-2025-24224
- CVE-2025-31223
- CVE-2025-31238
- CVE-2025-24223
- CVE-2025-31204
- CVE-2025-31205
- CVE-2025-31257
- CVE-2025-43374
- CVE-2025-31216
- CVE-2025-31214
- CVE-2025-31225
- CVE-2025-31253
- CVE-2025-31207
- CVE-2025-31227
- CVE-2025-31234
- CVE-2025-31260
- CVE-2025-24222
- CVE-2025-31236
- CVE-2025-30443
- CVE-2025-31218
- CVE-2025-31256
- CVE-2025-31244
- CVE-2025-31258
- CVE-2025-31266
- CVE-2025-31249
- CVE-2025-31259
- CVE-2025-31250
- CVE-2025-31248
Frequently Asked Questions
What is the severity of CVE-2025-31221?
CVE-2025-31221 has been classified with a high severity rating due to its potential impact on device security.
How do I fix CVE-2025-31221?
To fix CVE-2025-31221, update your Apple devices to the latest versions of macOS Ventura, macOS Sequoia, macOS Sonoma, tvOS, iPadOS, iOS, or watchOS as applicable.
Which products are affected by CVE-2025-31221?
CVE-2025-31221 affects various Apple products including specific versions of macOS Ventura, macOS Sequoia, macOS Sonoma, tvOS, iPadOS, iOS, and watchOS.
What types of vulnerabilities does CVE-2025-31221 address?
CVE-2025-31221 addresses vulnerabilities related to memory handling and permissions issues across multiple Apple services.
Is there a workaround for CVE-2025-31221?
There are no known workarounds for CVE-2025-31221, so updating to the latest software version is recommended.