CVE-2025-31228: Use After Free
AirDrop. A permissions issue was addressed with additional restrictions.
Other sources
AppleJPEG. The issue was addressed with improved input sanitization.
— Apple
Audio. A double free issue was addressed with improved memory management.
— Apple
Baseband. This issue was addressed through improved state management.
— Apple
Call History. A privacy issue was addressed by removing sensitive data.
— Apple
Core Bluetooth. This issue was addressed through improved state management.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-24097
- CVE-2025-31251
- CVE-2025-31235
- CVE-2025-31208
- CVE-2025-31196
- CVE-2025-31209
- CVE-2025-31239
- CVE-2025-31233
- CVE-2025-24111
- CVE-2025-31210
- CVE-2025-30448
- CVE-2025-31226
- CVE-2025-24144
- CVE-2025-31219
- CVE-2025-31241
- CVE-2024-8176
- CVE-2025-24225
- CVE-2025-31228
- CVE-2025-24259
- CVE-2025-31245
- CVE-2025-31221
- CVE-2025-31213
- CVE-2025-31242
- CVE-2025-31220
- CVE-2025-24213
- CVE-2025-31217
- CVE-2025-31215
- CVE-2025-31206
- CVE-2025-31216
- CVE-2025-43374
- CVE-2025-31214
- CVE-2025-31225
- CVE-2025-31212
- CVE-2025-31253
- CVE-2025-31207
- CVE-2025-24224
- CVE-2025-31222
- CVE-2025-31227
- CVE-2025-31234
- CVE-2025-31223
- CVE-2025-31238
- CVE-2025-24223
- CVE-2025-31204
- CVE-2025-31205
- CVE-2025-31257
Frequently Asked Questions
What is the severity of CVE-2025-31228?
The severity of CVE-2025-31228 has not been explicitly stated, but it addresses multiple vulnerabilities that could impact system security.
How do I fix CVE-2025-31228?
To fix CVE-2025-31228, update your iPhone or iPad to iOS version 18.5 or iPadOS version 17.7.7 as applicable.
What types of issues does CVE-2025-31228 address?
CVE-2025-31228 addresses issues related to permissions, input sanitization, memory management, and state management.
Which Apple products are affected by CVE-2025-31228?
CVE-2025-31228 affects various versions of Apple iOS and iPadOS, specifically versions 17.7.7 and 18.5.
Is there a mitigation for CVE-2025-31228 if I cannot update my system?
There are no specific mitigations mentioned for CVE-2025-31228 apart from updating to the latest software version.