CVE-2025-31253: Use After Free
AppleJPEG. The issue was addressed with improved input sanitization.
Other sources
Baseband. This issue was addressed through improved state management.
— Apple
Call History. A privacy issue was addressed by removing sensitive data.
— Apple
Core Bluetooth. This issue was addressed through improved state management.
— Apple
CoreAudio. The issue was addressed with improved checks.
— Apple
CoreGraphics. An out-of-bounds read was addressed with improved bounds checking.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-31251
- CVE-2025-31214
- CVE-2025-31225
- CVE-2025-31212
- CVE-2025-31208
- CVE-2025-31209
- CVE-2025-31239
- CVE-2025-31233
- CVE-2025-31253
- CVE-2025-31210
- CVE-2025-31207
- CVE-2025-30448
- CVE-2025-31226
- CVE-2025-24224
- CVE-2025-31219
- CVE-2025-31241
- CVE-2024-8176
- CVE-2025-24225
- CVE-2025-31222
- CVE-2025-31228
- CVE-2025-31227
- CVE-2025-31245
- CVE-2025-31234
- CVE-2025-31221
- CVE-2025-31242
- CVE-2025-24213
- CVE-2025-31223
- CVE-2025-31238
- CVE-2025-24223
- CVE-2025-31204
- CVE-2025-31217
- CVE-2025-31215
- CVE-2025-31206
- CVE-2025-31205
- CVE-2025-31257
- CVE-2025-31216
- CVE-2025-43374
Frequently Asked Questions
What is the severity of CVE-2025-31253?
CVE-2025-31253 has been classified with a moderate severity level due to privacy and state management issues.
How do I fix CVE-2025-31253?
To fix CVE-2025-31253, update your Apple iOS or iPadOS to version 18.5 or later.
Which devices are affected by CVE-2025-31253?
CVE-2025-31253 affects devices running Apple iOS and iPadOS versions prior to 18.5.
What types of issues does CVE-2025-31253 address?
CVE-2025-31253 addresses issues related to input sanitization, state management, and data privacy.
Is CVE-2025-31253 applicable to macOS?
Yes, CVE-2025-31253 can also be applicable to macOS versions prior to the fix in 18.5.