CVE-2025-31281

CRITICAL

iPadOS < 18.6 - Denial of Service via Maliciously Crafted File

Title source: llm
STIX 2.1

Description

An input validation issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6. Processing a maliciously crafted file may lead to unexpected app termination.

Scores

CVSS v3 9.1
EPSS 0.0054
EPSS Percentile 67.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20
Status published
Products (9)
Apple/iOS and iPadOS < 18.6
apple/ipados < 18.6
apple/iphone_os < 18.6
apple/macos < 15.6
Apple/macOS < 15.6
apple/tvos < 18.6
Apple/tvOS < 18.6
apple/visionos < 2.6
Apple/visionOS < 2.6
Published Jul 30, 2025
Tracked Since Feb 18, 2026