CVE-2025-31267

MEDIUM

App Store Connect < 3.0 - Unauthenticated Sensitive Information Exposure via Physical Access

Title source: llm
STIX 2.1

Description

An authentication issue was addressed with improved state management. This issue is fixed in App Store Connect 3.0. An attacker with physical access to an unlocked device may be able to view sensitive user information.

References (1)

Core 1
Core References

Scores

CVSS v3 4.6
EPSS 0.0007
EPSS Percentile 22.3%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (2)
Apple/App Store Connect < 3.0
apple/app_store_connect < 3.0
Published Jul 10, 2025
Tracked Since Feb 18, 2026