CVE-2025-31254: Input Validation
Published Sep 15, 2025
·Updated
Apple Neural Engine. An out-of-bounds access issue was addressed with improved bounds checking.
Credit
@@RenwaX23, Evan Waelde, Jaydev Ahire, Big Bear, an anonymous researcher, Ignacio Sanmillan@@ulexec, Mike Cardwell(grepular), Bob Lord, Pawel Wylecial(REDTEAM), Mickey Jin@@patch1t, Hossein Lotfi@@hosselot(Trend Micro Zero Day Initiative), Michael Reeves@@IntegralPilot, Nikita Sakalouski, Csaba Fitzl@@theevilbit(Kandji), Rosyna Keller(Totally Not Malicious Software), Guilherme Rambo(Best Buddy Apps), Yinyi Wu@@_3ndy1(Dawn Security Lab of JD), @@zlluny(Trend Micro Zero Day Initiative), 이동하 (Lee Dong Ha)(SSA Lab), Keisuke Hosoda, Viktor Oreshkin, Philipp Baldauf, Minghao Lin@@Y1nKoc, Lyutoon@@Lyutoon_, YingQi Shi@@Mas0n, Dawuge(Shuffle Team), Tom Brzezinski, Abhay Kailasia@@abhay_kailasia(C), KPC(Cisco Talos), 정답이 아닌 해답, Richard Hyunho Im@@richeeta, Noah Gregory (wts.dev), CVE-2025-6965, JZ, Seo Hyun-gyu@@wh1te4ever, Luke Roberts@@rookuu
Affected Software
6 affected componentsFixes available
Apple iOS<26
26
Apple iPadOS<26
26
Apple Safari<26
26
Apple Safari<26.0
Apple iPadOS<26.0
Apple iPhone OS<26.0
Event History
Sep 15, 2025
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
CVE Published
via MITRE·10:34 PM
Data Sourced
via MITRE·10:34 PM
DescriptionWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-31254?
CVE-2025-31254 has been reported with a high severity level due to multiple out-of-bounds access issues.
2
How do I fix CVE-2025-31254?
To remediate CVE-2025-31254, users should update their Apple devices to the latest version of iOS or iPadOS.
3
Which devices are affected by CVE-2025-31254?
CVE-2025-31254 affects Apple devices running iOS and iPadOS versions prior to 26.
4
What types of issues does CVE-2025-31254 address?
CVE-2025-31254 addresses out-of-bounds access issues and permissions issues within various components of Apple software.
5
Can CVE-2025-31254 lead to potential exploits?
Yes, the vulnerabilities described in CVE-2025-31254 may allow attackers to exploit the out-of-bounds access for unauthorized access or manipulation.