CVE-2025-31246: Buffer Overflow
Published May 12, 2025
·Updated
afpfs. The issue was addressed with improved memory handling.
Credit
Joseph Ravichandran@@0xjprx(MIT CSAIL), Dave G., Hossein Lotfi@@hosselot(Trend Micro Zero Day Initiative), Dillon Franke(Google Project Zero), wac(Trend Micro Zero Day Initiative), Csaba Fitzl@@theevilbit(Kandji), an anonymous researcher, Lyutoon(Atredis Partners), YenKoc(Atredis Partners), Dayton Pidhirney(Atredis Partners), Mateusz Krzywicki@@krzywix, Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), Lucas Leong@@_wmliang_(Trend Micro Zero Day Initiative), Christian Kohlschütter, CVE-2024-8176, Paweł Płatek (Trail(Bits), LFY@@secsys(Fudan University), CVE-2025-26465, CVE-2025-26466, wac, Kirin@@Pwnrin, 7feilee, Eric Dorphy(Twin Cities App Dev LLC), Adam M., Thomas Völkl@@vollkorntomate, SEEMOO, TU Darmstadt, Guilherme Rambo(Best Buddy Apps), Kirin@@Pwnrin(Fudan University), Bohdan Stasiuk@@bohdan_stasiuk, Saagar Jha, Tony Iskow@@Tybbow, Sourabhkumar Mishra, CertiK@@CertiK, @@RenwaX23, Ryan Dowd@@_rdowd, Noah Gregory (wts.dev), Google V8 Security Team, Andreas Jaegersberger & Ro Achterberg(Nosebeard Labs), Jiming Wang, Jikai Ren, Nan Wang@@eternalsakura13, rheza@@ginggilBesel(Palo Alto Networks), Edouard Bochin@@le_douds(Palo Alto Networks), Tao Yan@@Ga1ois(Palo Alto Networks), Yuhao Hu, Yan Kang, Chenggang Wu, Xiaojie Wei, Ignacio Sanmillan@@ulexec, Ivan Fratric(Google Project Zero), Juergen Schmied(Lynck GmbH), jioundai(360 Vulnerability Research Institute), chen fengjiao(HBC)
Affected Software
4 affected componentsFixes available
Apple macOS<14.7.6
14.7.6
macOS<15.5
15.5
macOS<14.7.6
macOS>=15.0<15.5
Event History
May 12, 2025
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
CVE Published
via MITRE·09:42 PM
Data Sourced
via MITRE·09:42 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-31246?
CVE-2025-31246 is considered a moderate severity vulnerability impacting memory handling in afpfs.
2
What impact does CVE-2025-31246 have on my system?
CVE-2025-31246 may lead to unexpected behavior or crashes in applications using the affected afpfs functionality.
3
How do I fix CVE-2025-31246?
To fix CVE-2025-31246, update your macOS to version 14.7.7 or later for macOS Sonoma, or 15.5.1 or later for macOS Sequoia.
4
Which versions of macOS are affected by CVE-2025-31246?
CVE-2025-31246 affects macOS Sonoma up to version 14.7.6 and macOS Sequoia up to version 15.5.
5
Is my data at risk due to CVE-2025-31246?
While CVE-2025-31246 does pose potential reliability issues, there is no direct indication that it compromises user data.