CVE-2025-31240: Input Validation
Published May 12, 2025
·Updated
afpfs. The issue was addressed with improved memory handling.
Credit
Joseph Ravichandran@@0xjprx(MIT CSAIL), Dave G., Hossein Lotfi@@hosselot(Trend Micro Zero Day Initiative), Dillon Franke(Google Project Zero), wac(Trend Micro Zero Day Initiative), Csaba Fitzl@@theevilbit(Kandji), an anonymous researcher, Lyutoon(Atredis Partners), YenKoc(Atredis Partners), Dayton Pidhirney(Atredis Partners), Mateusz Krzywicki@@krzywix, Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), Lucas Leong@@_wmliang_(Trend Micro Zero Day Initiative), Christian Kohlschütter, CVE-2024-8176, Paweł Płatek (Trail(Bits), LFY@@secsys(Fudan University), CVE-2025-26465, CVE-2025-26466, wac, Kirin@@Pwnrin, 7feilee, Eric Dorphy(Twin Cities App Dev LLC), Adam M., Lyutoon, YenKoc, Thomas Völkl@@vollkorntomate, SEEMOO, TU Darmstadt, Guilherme Rambo(Best Buddy Apps), Kirin@@Pwnrin(Fudan University), Bohdan Stasiuk@@bohdan_stasiuk, Saagar Jha, Tony Iskow@@Tybbow, Sourabhkumar Mishra, CertiK@@CertiK, @@RenwaX23, Ryan Dowd@@_rdowd, Noah Gregory (wts.dev), Google V8 Security Team, Andreas Jaegersberger & Ro Achterberg(Nosebeard Labs), Jiming Wang, Jikai Ren, Nan Wang@@eternalsakura13, rheza@@ginggilBesel(Palo Alto Networks), Edouard Bochin@@le_douds(Palo Alto Networks), Tao Yan@@Ga1ois(Palo Alto Networks), Yuhao Hu, Yan Kang, Chenggang Wu, Xiaojie Wei, Ignacio Sanmillan@@ulexec, Ivan Fratric(Google Project Zero), Juergen Schmied(Lynck GmbH), jioundai(360 Vulnerability Research Institute), chen fengjiao(HBC)
Affected Software
6 affected componentsFixes available
Apple macOS<14.7.6
14.7.6
macOS<15.5
15.5
macOS Ventura<13.7.6
13.7.6
macOS<13.7.6
macOS>=14.0<14.7.6
macOS>=15.0<15.5
Event History
May 12, 2025
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
CVE Published
via MITRE·09:42 PM
Data Sourced
via MITRE·09:42 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-31240?
CVE-2025-31240 has been assigned a severity rating that indicates a potentially impactful vulnerability affecting specific versions of macOS.
2
How do I fix CVE-2025-31240?
To fix CVE-2025-31240, update your Apple macOS to the latest version that addresses the vulnerability.
3
Which versions of macOS are affected by CVE-2025-31240?
CVE-2025-31240 affects Apple macOS Sonoma up to version 14.7.6, macOS Sequoia up to version 15.5, and macOS Ventura up to version 13.7.6.
4
What causes CVE-2025-31240?
CVE-2025-31240 is caused by improper memory handling in the afpfs component of macOS.
5
Is CVE-2025-31240 exploited in the wild?
As of now, there have been no confirmed reports of CVE-2025-31240 being actively exploited in the wild.