CVE-2025-31214

Severity CVSS v4.0:
Pending analysis
Type:
CWE-300 Channel Accessible by Non-Endpoint
Publication date:
12/05/2025
Last modified:
03/11/2025

Description

This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPadOS 18.5. An attacker in a privileged network position may be able to intercept network traffic.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* 18.5 (excluding)
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* 18.5 (excluding)