CVE-2025-31227: Use After Free
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. An attacker with physical access to a device may be able to access a deleted call recording.
Other sources
AppleJPEG. The issue was addressed with improved input sanitization.
— Apple
Baseband. This issue was addressed through improved state management.
— Apple
Call History. A privacy issue was addressed by removing sensitive data.
— Apple
Core Bluetooth. This issue was addressed through improved state management.
— Apple
CoreAudio. The issue was addressed with improved checks.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-31251
- CVE-2025-31214
- CVE-2025-31225
- CVE-2025-31212
- CVE-2025-31208
- CVE-2025-31209
- CVE-2025-31239
- CVE-2025-31233
- CVE-2025-31253
- CVE-2025-31210
- CVE-2025-31207
- CVE-2025-30448
- CVE-2025-31226
- CVE-2025-24224
- CVE-2025-31219
- CVE-2025-31241
- CVE-2024-8176
- CVE-2025-24225
- CVE-2025-31222
- CVE-2025-31228
- CVE-2025-31227
- CVE-2025-31245
- CVE-2025-31234
- CVE-2025-31221
- CVE-2025-31242
- CVE-2025-24213
- CVE-2025-31223
- CVE-2025-31238
- CVE-2025-24223
- CVE-2025-31204
- CVE-2025-31217
- CVE-2025-31215
- CVE-2025-31206
- CVE-2025-31205
- CVE-2025-31257
- CVE-2025-31216
- CVE-2025-43374
Frequently Asked Questions
What is the severity of CVE-2025-31227?
CVE-2025-31227 is classified as a high-severity vulnerability due to the potential for data exposure and unauthorized access.
How do I fix CVE-2025-31227?
To fix CVE-2025-31227, users should update their devices to the latest version of iOS or iPadOS, specifically version 18.5 or later.
What products are affected by CVE-2025-31227?
CVE-2025-31227 affects Apple iOS and iPadOS versions prior to 18.5.
What types of issues does CVE-2025-31227 address?
CVE-2025-31227 addresses issues related to input sanitization, state management, and privacy concerns involving sensitive data.
Is there a permanent fix for CVE-2025-31227?
Yes, the permanent fix for CVE-2025-31227 is to ensure your device runs on iOS or iPadOS version 18.5 or later.