CVE-2025-31246: Buffer Overflow
afpfs. The issue was addressed with improved memory handling.
Other sources
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6. Connecting to a malicious AFP server may corrupt kernel memory.
— MITRE
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-31246
- CVE-2025-31240
- CVE-2025-31237
- CVE-2025-31251
- CVE-2025-31235
- CVE-2025-31208
- CVE-2025-31196
- CVE-2025-31209
- CVE-2025-31239
- CVE-2025-31233
- CVE-2025-30453
- CVE-2025-24258
- CVE-2025-30448
- CVE-2025-31232
- CVE-2025-24144
- CVE-2025-31219
- CVE-2025-31241
- CVE-2024-8176
- CVE-2025-30440
- CVE-2025-31222
- CVE-2025-24274
- CVE-2025-24142
- CVE-2025-26465
- CVE-2025-26466
- CVE-2025-31245
- CVE-2025-31224
- CVE-2025-31221
- CVE-2025-31213
- CVE-2025-31247
- CVE-2025-30442
- CVE-2025-31242
- CVE-2025-31220
- CVE-2025-24155
- CVE-2025-31260
- CVE-2025-24222
- CVE-2025-31212
- CVE-2025-31236
- CVE-2025-30443
- CVE-2025-31226
- CVE-2025-24224
- CVE-2025-31218
- CVE-2025-31256
- CVE-2025-31234
- CVE-2025-31244
- CVE-2025-31258
- CVE-2025-31266
- CVE-2025-31249
- CVE-2025-31259
- CVE-2025-31250
- CVE-2025-31248
- CVE-2025-24213
- CVE-2025-31223
- CVE-2025-31238
- CVE-2025-31215
- CVE-2025-31204
- CVE-2025-24223
- CVE-2025-31206
- CVE-2025-31217
- CVE-2025-31205
- CVE-2025-31257
- CVE-2025-43374
Frequently Asked Questions
What is the severity of CVE-2025-31246?
CVE-2025-31246 is considered a moderate severity vulnerability impacting memory handling in afpfs.
What impact does CVE-2025-31246 have on my system?
CVE-2025-31246 may lead to unexpected behavior or crashes in applications using the affected afpfs functionality.
How do I fix CVE-2025-31246?
To fix CVE-2025-31246, update your macOS to version 14.7.7 or later for macOS Sonoma, or 15.5.1 or later for macOS Sequoia.
Which versions of macOS are affected by CVE-2025-31246?
CVE-2025-31246 affects macOS Sonoma up to version 14.7.6 and macOS Sequoia up to version 15.5.
Is my data at risk due to CVE-2025-31246?
While CVE-2025-31246 does pose potential reliability issues, there is no direct indication that it compromises user data.