Apple Security Advisories · May 2025 — Apple Security Advisories
62 advisories 62 CVEs 1 EXPLOITED

Apple-vendor CVEs for 2025-05. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2023-43010

iPadOSExploitedCISA KEV listedCRITICAL2025-05-29

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS 16.7.15, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to...

CVEs:CVE-2023-43010

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
Upstream advisory

CVE-2025-24225

iPadOSActive exploitation (sightings)MEDIUM2025-05-12

An injection issue was addressed with improved input validation. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. Processing an email may lead to user interface spoofing.

CVEs:CVE-2025-24225

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2025-24222

macOSActive exploitation (sightings)HIGH2025-05-12

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5. Processing maliciously crafted web content may lead to an unexpected process crash.

CVEs:CVE-2025-24222

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31266

macOSActive exploitation (sightings)MEDIUM2025-05-12

A spoofing issue was addressed with improved truncation when displaying the fully qualified domain name. This issue is fixed in Safari 18.5, macOS Sequoia 15.5. A website may be able to spoof the domain name in the title of a pop-up window.

CVEs:CVE-2025-31266

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
safari affected apple
Upstream advisory

CVE-2025-31216

iPadOSActive exploitation (sightings)LOW2025-05-12

The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An attacker with physical access to a device may be able to override managed Wi-Fi profiles.

CVEs:CVE-2025-31216

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2025-31208

visionOSPoC exploitHIGH2025-05-12

The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. Parsing a file may lead to an unexpected...

CVEs:CVE-2025-31208

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-31233

visionOSPoC exploitMEDIUM2025-05-12

The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing a maliciously cra...

CVEs:CVE-2025-31233

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-31257

visionOSPoC exploitHIGH2025-05-12

This issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to an unexpected Safari...

CVEs:CVE-2025-31257

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-31219

visionOSPoC exploitHIGH2025-05-12

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. An attacker may be able to caus...

CVEs:CVE-2025-31219

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-30448

visionOSPoC exploitCRITICAL2025-05-12

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, visionOS 2.5. An attacker may be able to turn on sharing of an i...

CVEs:CVE-2025-30448

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
visionos affected apple
Upstream advisory

CVE-2025-31221

visionOSPoC exploitCRITICAL2025-05-12

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. A remote attacker ma...

CVEs:CVE-2025-31221

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-31238

visionOSPoC exploitCRITICAL2025-05-12

The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to memory corruption.

CVEs:CVE-2025-31238

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-31241

visionOSPoC exploitCRITICAL2025-05-12

A double free issue was addressed with improved memory management. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. A remote attacker m...

CVEs:CVE-2025-31241

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-31209

visionOSPoC exploitMEDIUM2025-05-12

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. Parsing a file may ...

CVEs:CVE-2025-31209

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-31217

visionOSPoC exploitHIGH2025-05-12

The issue was addressed with improved input validation. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to an un...

CVEs:CVE-2025-31217

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-31239

visionOSPoC exploitCRITICAL2025-05-12

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. Parsing a file m...

CVEs:CVE-2025-31239

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-31237

macOSPoC exploitHIGH2025-05-12

This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. Mounting a maliciously crafted AFP network share may lead to system termination.

CVEs:CVE-2025-31237

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31240

macOSPoC exploitHIGH2025-05-12

This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. Mounting a maliciously crafted AFP network share may lead to system termination.

CVEs:CVE-2025-31240

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31213

iPadOSPoC exploitHIGH2025-05-12

A logging issue was addressed with improved data redaction. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be able to access associated usernames and websites in a user's iCloud Keychain.

CVEs:CVE-2025-31213

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
macos affected apple
Upstream advisory

CVE-2025-31223

visionOSPoC exploitCRITICAL2025-05-12

The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to memory corruption.

CVEs:CVE-2025-31223

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-31234

visionOSPoC exploitHIGH2025-05-12

The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5. An attacker may be able to cause unexpected system termination or corrupt kernel memory.

CVEs:CVE-2025-31234

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-31246

macOSPoC exploitHIGH2025-05-12

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6. Connecting to a malicious AFP server may corrupt kernel memory.

CVEs:CVE-2025-31246

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31210

iPadOSPoC exploitHIGH2025-05-12

The issue was addressed with improved UI. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. Processing web content may lead to a denial-of-service.

CVEs:CVE-2025-31210

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2025-31214

iPadOSPoC exploitHIGH2025-05-12

This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPadOS 18.5. An attacker in a privileged network position may be able to intercept network traffic.

CVEs:CVE-2025-31214

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2025-43480

visionOSPoC exploitHIGH2025-05-29

The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious website may exfiltrate data cross-origin.

CVEs:CVE-2025-43480

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-31247

macOSPoC exploitHIGH2025-05-12

A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An attacker may gain access to protected parts of the file system.

CVEs:CVE-2025-31247

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31258

macOSPoC exploitMEDIUM2025-05-12

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5. An app may be able to break out of its sandbox.

CVEs:CVE-2025-31258

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31205

visionOSPoC exploitMEDIUM2025-05-12

The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. A malicious website may exfiltrate data cross-origin.

CVEs:CVE-2025-31205

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-31225

iPadOSPoC exploitHIGH2025-05-12

A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.5 and iPadOS 18.5. Call history from deleted apps may still appear in spotlight search results.

CVEs:CVE-2025-31225

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2025-31232

macOSPoC exploitHIGH2025-05-12

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. A sandboxed app may be able to access sensitive user data.

CVEs:CVE-2025-31232

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31228

iPadOSPoC exploitMEDIUM2025-05-12

The issue was addressed with improved authentication. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An attacker with physical access to a device may be able to access notes from the lock screen.

CVEs:CVE-2025-31228

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2025-31251

visionOSPoC exploitMEDIUM2025-05-12

The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing a maliciously cra...

CVEs:CVE-2025-31251

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-31249

macOSPoC exploitHIGH2025-05-12

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive user data.

CVEs:CVE-2025-31249

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31227

iPadOSPoC exploitMEDIUM2025-05-12

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. An attacker with physical access to a device may be able to access a deleted call recording.

CVEs:CVE-2025-31227

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2025-31207

iPadOSPoC exploitHIGH2025-05-12

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. An app may be able to enumerate a user's installed apps.

CVEs:CVE-2025-31207

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2025-31222

visionOSPoC exploitHIGH2025-05-12

A correctness issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. A user may be able to elevate privileges.

CVEs:CVE-2025-31222

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-31226

visionOSPoC exploitHIGH2025-05-12

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing a maliciously crafted image may lead to a denial-of-service.

CVEs:CVE-2025-31226

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-31196

visionOSPoC exploitHIGH2025-05-12

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing a malic...

CVEs:CVE-2025-31196

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
macos affected apple
Upstream advisory

CVE-2025-31259

macOSPoC exploitHIGH2025-05-12

A privacy issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to capture a screenshot of an app entering or exiting full screen mode.

CVEs:CVE-2025-31259

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24220

iPadOSPoC exploitMEDIUM2025-05-12

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.9. An app may be able to read a persistent device identifier.

CVEs:CVE-2025-24220

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2025-24111

visionOSPoC exploitCRITICAL2025-05-12

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.7, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3, watchOS 11.3. An app may be ...

CVEs:CVE-2025-24111

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-24274

macOSPoC exploitCRITICAL2025-05-12

An input validation issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. A malicious app may be able to gain root privileges.

CVEs:CVE-2025-24274

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24144

visionOSPoC exploitHIGH2025-05-12

An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.7, macOS Sequoia 15.3, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.3, visionOS 2.3, watchOS 11.3. An app ...

CVEs:CVE-2025-24144

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-31242

iPadOSPoC exploitMEDIUM2025-05-12

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.3, macOS Sonoma 14.7.6, macOS Ventura 13.7.3, macOS Ventura 13.7.6...

CVEs:CVE-2025-31242

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
macos affected apple
Upstream advisory

CVE-2025-24155

macOSPoC exploitMEDIUM2025-05-12

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be able to disclose kernel memory.

CVEs:CVE-2025-24155

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31224

macOSPoC exploitHIGH2025-05-12

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be able to bypass certain Privacy preferences.

CVEs:CVE-2025-31224

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-30442

macOSPoC exploitHIGH2025-05-12

The issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be able to gain elevated privileges.

CVEs:CVE-2025-30442

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31218

macOSPoC exploitMEDIUM2025-05-12

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5. An app may be able to observe the hostnames of new network connections.

CVEs:CVE-2025-31218

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31245

visionOSPoC exploitMEDIUM2025-05-12

The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5. An app may be able to cause unexpected system terminat...

CVEs:CVE-2025-31245

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-31253

iPadOSPoC exploitHIGH2025-05-12

This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPadOS 18.5. Muting the microphone during a FaceTime call may not result in audio being silenced.

CVEs:CVE-2025-31253

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2025-24142

macOSPoC exploitMEDIUM2025-05-12

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be able to access sensitive user data.

CVEs:CVE-2025-24142

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31220

iPadOSPoC exploitHIGH2025-05-12

A privacy issue was addressed by removing sensitive data. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. A malicious app may be able to read sensitive location information.

CVEs:CVE-2025-31220

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
macos affected apple
Upstream advisory

CVE-2025-31212

visionOSPoC exploitMEDIUM2025-05-12

This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. An app may be able to access sensitive user data.

CVEs:CVE-2025-31212

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-24258

macOSPoC exploitCRITICAL2025-05-12

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be able to gain root privileges.

CVEs:CVE-2025-24258

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31250

macOSPoC exploitHIGH2025-05-12

An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive user data.

CVEs:CVE-2025-31250

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-30440

macOSPoC exploitMEDIUM2025-05-12

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be able to bypass ASLR.

CVEs:CVE-2025-30440

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-30453

macOSPoC exploitCRITICAL2025-05-12

The issue was addressed with additional permissions checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. A malicious app may be able to gain root privileges.

CVEs:CVE-2025-30453

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31235

iPadOSPoC exploitCRITICAL2025-05-12

A double free issue was addressed with improved memory management. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be able to cause unexpected system termination.

CVEs:CVE-2025-31235

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
macos affected apple
Upstream advisory

CVE-2025-31236

macOSPoC exploitHIGH2025-05-12

An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive user data.

CVEs:CVE-2025-31236

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31244

macOSPoC exploitHIGH2025-05-12

A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.5. An app may be able to break out of its sandbox.

CVEs:CVE-2025-31244

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31256

macOSPoC exploitMEDIUM2025-05-12

The issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.5. Hot corner may unexpectedly reveal a user’s deleted notes.

CVEs:CVE-2025-31256

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31260

macOSPoC exploitMEDIUM2025-05-12

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive user data.

CVEs:CVE-2025-31260

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.