CVE-2025-31196

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

History

02 Apr 2026, 19:19

Type Values Removed Values Added
References
  • () https://support.apple.com/en-us/122371 -
  • () https://support.apple.com/en-us/122373 -
  • () https://support.apple.com/en-us/122376 -
  • () https://support.apple.com/en-us/122377 -
  • () https://support.apple.com/en-us/122378 -
Summary (en) An out-of-bounds read was addressed with improved input validation. This issue is fixed in iPadOS 17.7.7, macOS Ventura 13.7.6, macOS Sonoma 14.7.6. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents. (en) An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.

03 Nov 2025, 20:18

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2025/May/6 -
  • () http://seclists.org/fulldisclosure/2025/May/9 -

27 May 2025, 13:57

Type Values Removed Values Added
CPE cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
First Time Apple macos
Apple
Apple ipados
References () https://support.apple.com/en-us/122405 - () https://support.apple.com/en-us/122405 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122717 - () https://support.apple.com/en-us/122717 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122718 - () https://support.apple.com/en-us/122718 - Release Notes, Vendor Advisory

13 May 2025, 20:15

Type Values Removed Values Added
CWE CWE-125
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

13 May 2025, 19:35

Type Values Removed Values Added
Summary
  • (es) Se solucionó una lectura fuera de los límites mejorando la validación de entrada. Este problema se solucionó en iPadOS 17.7.7, macOS Ventura 13.7.6 y macOS Sonoma 14.7.6. Procesar un archivo manipulado con fines maliciosos puede provocar una denegación de servicio o la posible divulgación del contenido de la memoria.

12 May 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-12 22:15

Updated : 2026-04-02 19:19


NVD link : CVE-2025-31196

Mitre link : CVE-2025-31196

CVE.ORG link : CVE-2025-31196


JSON object : View

Products Affected

apple

  • ipados
  • macos
CWE
CWE-125

Out-of-bounds Read