CVE-2025-31248: Race Condition
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to access sensitive user data.
Other sources
afpfs. The issue was addressed with improved memory handling.
— Apple
afpfs. This issue was addressed with improved checks.
— Apple
AirPlay. A type confusion issue was addressed with improved checks.
— Apple
Apple Intelligence Reports. A permissions issue was addressed with additional restrictions.
— Apple
AppleGraphicsControl. The issue was addressed with improved checks.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-24109
- CVE-2025-24100
- CVE-2025-24114
- CVE-2025-24121
- CVE-2025-24122
- CVE-2025-24127
- CVE-2025-24106
- CVE-2024-44172
- CVE-2025-24123
- CVE-2025-24124
- CVE-2025-24102
- CVE-2025-24174
- CVE-2025-24086
- CVE-2025-24094
- CVE-2025-24115
- CVE-2025-24116
- CVE-2024-55549
- CVE-2025-24855
- CVE-2025-24136
- CVE-2025-24099
- CVE-2025-24130
- CVE-2025-24183
- CVE-2025-24146
- CVE-2024-54497
- CVE-2025-24093
- CVE-2025-24149
- CVE-2025-24103
- CVE-2025-24185
- CVE-2025-24139
- CVE-2025-24151
- CVE-2025-24138
- CVE-2025-24176
- CVE-2025-31242
- CVE-2025-31248
- CVE-2025-24154
- CVE-2025-43374
- CVE-2025-24120
- CVE-2025-24156
- CVE-2025-24137
- CVE-2025-24112
- CVE-2024-54509
- CVE-2025-24161
- CVE-2025-24160
- CVE-2025-24163
- CVE-2025-24118
- CVE-2025-24159
- CVE-2024-44243
- CVE-2025-24092
- CVE-2025-31246
- CVE-2025-31240
- CVE-2025-31237
- CVE-2025-31260
- CVE-2025-31251
- CVE-2025-31235
- CVE-2025-24222
- CVE-2025-31212
- CVE-2025-31208
- CVE-2025-31209
- CVE-2025-31239
- CVE-2025-31233
- CVE-2025-31236
- CVE-2025-30443
- CVE-2025-31226
- CVE-2025-31232
- CVE-2025-24224
- CVE-2025-31241
- CVE-2025-31219
- CVE-2024-8176
- CVE-2025-30440
- CVE-2025-31222
- CVE-2025-24274
- CVE-2025-31218
- CVE-2025-31256
- CVE-2025-24142
- CVE-2025-26465
- CVE-2025-26466
- CVE-2025-31234
- CVE-2025-31245
- CVE-2025-31244
- CVE-2025-31258
- CVE-2025-31266
- CVE-2025-31249
- CVE-2025-31224
- CVE-2025-31221
- CVE-2025-31213
- CVE-2025-31247
- CVE-2025-31259
- CVE-2025-31250
- CVE-2025-31220
- CVE-2025-24213
- CVE-2025-31223
- CVE-2025-31238
- CVE-2025-31215
- CVE-2025-31204
- CVE-2025-24223
- CVE-2025-31206
- CVE-2025-31217
- CVE-2025-31205
- CVE-2025-31257
Frequently Asked Questions
What is the severity of CVE-2025-31248?
CVE-2025-31248 has been classified with a severity rating that indicates significant risk to sensitive user data.
How do I fix CVE-2025-31248?
To mitigate CVE-2025-31248, upgrade to macOS Ventura 13.7.3, macOS Sequoia 15.5, or macOS Sonoma 14.7.3 or later.
What systems are affected by CVE-2025-31248?
CVE-2025-31248 affects macOS Ventura versions prior to 13.7.3, macOS Sequoia versions prior to 15.5, and macOS Sonoma versions prior to 14.7.3.
What kind of issue does CVE-2025-31248 address?
CVE-2025-31248 addresses a parsing issue in directory path handling that could lead to unauthorized access to sensitive user data.
Is CVE-2025-31248 being actively exploited?
Current reports indicate that CVE-2025-31248 has potential for exploitation due to its nature, emphasizing the importance of updating affected systems.