CVE-2025-31228

The issue was addressed with improved authentication. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An attacker with physical access to a device may be able to access notes from the lock screen.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

History

02 Apr 2026, 19:19

Type Values Removed Values Added
Summary (en) The issue was addressed with improved authentication. This issue is fixed in iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5. An attacker with physical access to a device may be able to access notes from the lock screen. (en) The issue was addressed with improved authentication. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An attacker with physical access to a device may be able to access notes from the lock screen.

03 Nov 2025, 20:18

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2025/May/5 -
  • () http://seclists.org/fulldisclosure/2025/May/6 -

27 May 2025, 21:27

Type Values Removed Values Added
First Time Apple iphone Os
Apple
Apple ipados
References () https://support.apple.com/en-us/122404 - () https://support.apple.com/en-us/122404 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122405 - () https://support.apple.com/en-us/122405 - Release Notes, Vendor Advisory
CPE cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*

13 May 2025, 20:15

Type Values Removed Values Added
CWE CWE-287
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.8

13 May 2025, 19:35

Type Values Removed Values Added
Summary
  • (es) El problema se solucionó mejorando la autenticación. Este problema está corregido en iPadOS 17.7.7, iOS 18.5 y iPadOS 18.5. Un atacante con acceso físico a un dispositivo podría acceder a las notas desde la pantalla de bloqueo.

12 May 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-12 22:15

Updated : 2026-04-02 19:19


NVD link : CVE-2025-31228

Mitre link : CVE-2025-31228

CVE.ORG link : CVE-2025-31228


JSON object : View

Products Affected

apple

  • ipados
  • iphone_os
CWE
CWE-287

Improper Authentication