CVE-2025-31225: Infoleak
A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.5 and iPadOS 18.5. Call history from deleted apps may still appear in spotlight search results.
Other sources
AppleJPEG. The issue was addressed with improved input sanitization.
— Apple
Baseband. This issue was addressed through improved state management.
— Apple
Call History. A privacy issue was addressed by removing sensitive data.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-31251
- CVE-2025-31214
- CVE-2025-31225
- CVE-2025-31212
- CVE-2025-31208
- CVE-2025-31209
- CVE-2025-31239
- CVE-2025-31233
- CVE-2025-31253
- CVE-2025-31210
- CVE-2025-31207
- CVE-2025-30448
- CVE-2025-31226
- CVE-2025-24224
- CVE-2025-31219
- CVE-2025-31241
- CVE-2024-8176
- CVE-2025-24225
- CVE-2025-31222
- CVE-2025-31228
- CVE-2025-31227
- CVE-2025-31245
- CVE-2025-31234
- CVE-2025-31221
- CVE-2025-31242
- CVE-2025-24213
- CVE-2025-31223
- CVE-2025-31238
- CVE-2025-24223
- CVE-2025-31204
- CVE-2025-31217
- CVE-2025-31215
- CVE-2025-31206
- CVE-2025-31205
- CVE-2025-31257
- CVE-2025-31216
- CVE-2025-43374
Frequently Asked Questions
What is the severity of CVE-2025-31225?
CVE-2025-31225 has been categorized as a high-severity vulnerability affecting Apple products.
How do I fix CVE-2025-31225?
To mitigate the effects of CVE-2025-31225, update your Apple iOS or iPadOS devices to version 18.5 or later.
Which Apple products are affected by CVE-2025-31225?
CVE-2025-31225 affects Apple iOS and iPadOS versions prior to 18.5.
What types of issues does CVE-2025-31225 address?
CVE-2025-31225 addresses issues related to input sanitization, baseband state management, and privacy concerning call history.
Is there a workaround for CVE-2025-31225 before updating?
There are no confirmed workarounds for CVE-2025-31225, so updating to the latest version is recommended for protection.