VDB
CVE-2025-31267
CVE-2025-31267
PUBLISHED
CVSS 4.599999904632568 MEDIUM
An authentication issue was addressed with improved state management. This issue is fixed in App Store Connect 3.0. An attacker with physical access to an unlocked device may be able to view sensitive user information.
EPSS 0.19% · 8.4th percentile
Risk Scores
CVSS 3.1
4.599999904632568
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.19%
8.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | App Store Connect | * |
| apple | app_store_connect | 0 |
Timeline
- Jul 10, 2025 CVE Published
- Jul 11, 2025 EPSS Score
- Jul 11, 2025 Coalition ESS Score
- Jul 14, 2025 PoC Published
- Jul 15, 2025 Coalition ESS Score
- Jul 20, 2025 EPSS Score
- Jul 29, 2025 Coalition ESS Score
- Jul 30, 2025 EPSS Score
- Aug 8, 2025 EPSS Score
- Aug 18, 2025 EPSS Score
- Aug 22, 2025 Coalition ESS Score
- Aug 26, 2025 Coalition ESS Score