An authentication issue was addressed with improved state management. This issue is fixed in App Store Connect 3.0. An attacker with physical access to an unlocked device may be able to view sensitive user information.
References
Link | Resource |
---|---|
https://support.apple.com/en-us/123356 | Vendor Advisory |
Configurations
History
29 Jul 2025, 18:08
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:apple:app_store_connect:*:*:*:*:*:*:*:* | |
First Time |
Apple app Store Connect
Apple |
|
References | () https://support.apple.com/en-us/123356 - Vendor Advisory |
15 Jul 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-287 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.6 |
15 Jul 2025, 13:14
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
10 Jul 2025, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-10 23:15
Updated : 2025-07-29 18:08
NVD link : CVE-2025-31267
Mitre link : CVE-2025-31267
CVE.ORG link : CVE-2025-31267
JSON object : View
Products Affected
apple
- app_store_connect
CWE
CWE-287
Improper Authentication