CVE-2025-31260
Published May 12, 2025
·Updated
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive user data.
Credit
Joseph Ravichandran@@0xjprx(MIT CSAIL), Dave G., Thomas Völkl@@vollkorntomate, SEEMOO, TU Darmstadt, Hossein Lotfi@@hosselot(Trend Micro Zero Day Initiative), Dillon Franke(Google Project Zero), wac(Trend Micro Zero Day Initiative), Guilherme Rambo(Best Buddy Apps), Kirin@@Pwnrin(Fudan University), LFY@@secsys(Fudan University), Bohdan Stasiuk@@bohdan_stasiuk, Saagar Jha, an anonymous researcher, Tony Iskow@@Tybbow, Christian Kohlschütter, Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), Lucas Leong@@_wmliang_(Trend Micro Zero Day Initiative), CVE-2024-8176, Paweł Płatek (Trail(Bits), Adam M., Sourabhkumar Mishra, CVE-2025-26465, CVE-2025-26466, CertiK@@CertiK, wac, Csaba Fitzl@@theevilbit(Kandji), @@RenwaX23, Ryan Dowd@@_rdowd, Kirin@@Pwnrin, 7feilee, Eric Dorphy(Twin Cities App Dev LLC), Noah Gregory (wts.dev), Google V8 Security Team, Andreas Jaegersberger & Ro Achterberg(Nosebeard Labs), Jiming Wang, Jikai Ren, Nan Wang@@eternalsakura13, rheza@@ginggilBesel(Palo Alto Networks), Edouard Bochin@@le_douds(Palo Alto Networks), Tao Yan@@Ga1ois(Palo Alto Networks), Yuhao Hu, Yan Kang, Chenggang Wu, Xiaojie Wei, Ignacio Sanmillan@@ulexec, Ivan Fratric(Google Project Zero), Juergen Schmied(Lynck GmbH), jioundai(360 Vulnerability Research Institute), chen fengjiao(HBC)
Affected Software
2 affected componentsFixes available
macOS<15.5
15.5
macOS<15.5
Event History
May 12, 2025
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
CVE Published
via MITRE·09:42 PM
Data Sourced
via MITRE·09:42 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-31260?
CVE-2025-31260 is rated as a moderate severity vulnerability.
2
How do I fix CVE-2025-31260?
To fix CVE-2025-31260, update your Apple macOS Sequoia to the latest version beyond 15.5.
3
What software is affected by CVE-2025-31260?
CVE-2025-31260 affects Apple macOS Sequoia version 15.5 and earlier.
4
What type of vulnerability is CVE-2025-31260?
CVE-2025-31260 is a permissions issue that can lead to unauthorized access.
5
What improvements were made in CVE-2025-31260?
CVE-2025-31260 was addressed with improved memory handling and additional restrictions.