CVE-2025-31281CRITICAL 9.1EPSS p59.9%

CVE-2025-31281CVE-2025-31281

Description

An input validation issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6. Processing a maliciously crafted file may lead to unexpected app termination.

Scoring

CVSS 3.19.1 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS1.05% probability of exploitation · percentile 59.9% · 2026-06-18T12:00:27Z
Published2025-07-30
Last modified2026-04-02

Underlying weaknesses· 1

CWE-20

References

  1. https://support.apple.com/en-us/124147
  2. https://support.apple.com/en-us/124149
  3. https://support.apple.com/en-us/124153
  4. https://support.apple.com/en-us/124154
  5. http://seclists.org/fulldisclosure/2025/Jul/30
  6. http://seclists.org/fulldisclosure/2025/Jul/32
  7. http://seclists.org/fulldisclosure/2025/Jul/36
  8. http://seclists.org/fulldisclosure/2025/Jul/37

1

TypeTargetConfidenceTier
WeaknessImproper Input Validationcwe-200%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-43186
CVE
CVE-2025-24211
CVE
CVE-2025-43234
CVE
CVE-2025-31234
CVE
CVE-2025-24190
CVE
CVE-2025-43202
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.