CVE-2025-31251: Medium severity Apple macOS Sonoma vulnerability
afpfs. The issue was addressed with improved memory handling.
Other sources
afpfs. This issue was addressed with improved checks.
— Apple
AirDrop. A permissions issue was addressed with additional restrictions.
— Apple
Apple Intelligence Reports. A permissions issue was addressed with additional restrictions.
— Apple
AppleJPEG. The issue was addressed with improved input sanitization.
— Apple
The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
— MITRE
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in 14.7.6 - Upgrade
Upgrade
macOS Venturato a version that resolves this vulnerability.Fixed in 13.7.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.7.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.5 - Upgrade
Upgrade
macOS Sequoiato a version that resolves this vulnerability.Fixed in 15.5 - Upgrade
Upgrade
macOS Sonomato a version that resolves this vulnerability.Fixed in 14.7.6 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 18.5 - Upgrade
Upgrade
visionOSto a version that resolves this vulnerability.Fixed in 2.5 - Upgrade
Upgrade
watchOSto a version that resolves this vulnerability.Fixed in 11.5
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-31246
- CVE-2025-31240
- CVE-2025-31237
- CVE-2025-31251
- CVE-2025-31235
- CVE-2025-31208
- CVE-2025-31196
- CVE-2025-31209
- CVE-2025-31239
- CVE-2025-31233
- CVE-2025-30453
- CVE-2025-24258
- CVE-2025-30448
- CVE-2025-31232
- CVE-2025-24144
- CVE-2025-31219
- CVE-2025-31241
- CVE-2024-8176
- CVE-2025-30440
- CVE-2025-31222
- CVE-2025-24274
- CVE-2025-24142
- CVE-2025-26465
- CVE-2025-26466
- CVE-2025-31245
- CVE-2025-31224
- CVE-2025-31221
- CVE-2025-31213
- CVE-2025-31247
- CVE-2025-30442
- CVE-2025-31242
- CVE-2025-31220
- CVE-2025-24155
- CVE-2025-31212
- CVE-2025-31200
- CVE-2025-31226
- CVE-2025-24224
- CVE-2025-24213
- CVE-2025-31223
- CVE-2025-31238
- CVE-2025-24223
- CVE-2025-31204
- CVE-2025-31217
- CVE-2025-31215
- CVE-2025-31206
- CVE-2025-31205
- CVE-2025-31257
- CVE-2025-43374
- CVE-2025-24097
- CVE-2025-24111
- CVE-2025-31210
- CVE-2025-24225
- CVE-2025-31228
- CVE-2025-24259
- CVE-2025-31216
- CVE-2025-31214
- CVE-2025-31225
- CVE-2025-31253
- CVE-2025-31207
- CVE-2025-31227
- CVE-2025-31234
- CVE-2025-31260
- CVE-2025-24222
- CVE-2025-31236
- CVE-2025-30443
- CVE-2025-31218
- CVE-2025-31256
- CVE-2025-31244
- CVE-2025-31258
- CVE-2025-31266
- CVE-2025-31249
- CVE-2025-31259
- CVE-2025-31250
- CVE-2025-31248
Frequently Asked Questions
What is the severity of CVE-2025-31251?
CVE-2025-31251 is classified with a high severity due to its potential impact on user permissions and memory handling.
How do I fix CVE-2025-31251?
To fix CVE-2025-31251, upgrade your affected Apple software to the latest version released by Apple.
What are the affected software versions for CVE-2025-31251?
CVE-2025-31251 affects several Apple products including macOS Sonoma up to 14.7.6, iPadOS up to 17.7.7, and others.
Does CVE-2025-31251 affect both iOS and macOS?
Yes, CVE-2025-31251 impacts both iOS and macOS, specifically in versions mentioned in the vulnerability report.
What improvements were made in relation to CVE-2025-31251?
CVE-2025-31251 was addressed with improved memory handling and additional permissions checks.