CVE-2025-31207 Details
Description
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. An app may be able to enumerate a user's installed apps.
A logic vulnerability allowing apps to enumerate a user's installed applications has been identified in Apple iOS and iPadOS. This issue affects iPhone XS and later models, as well as various iPad Pro, iPad Air, iPad, and iPad mini models, all through version 18.4. The vulnerability arises from insufficient checks, which could enable an app to access information about other installed apps on the device.
Users can update to iOS 18.5 or iPadOS 18.5 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://seclists.org/fulldisclosure/2025/May/5 | CVE | |
| https://support.apple.com/en-us/122404 | [email protected] | Release NotesVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| apple ipados | < 18.5 |
CPE
Remediation
| |
| apple iphone os | < 18.5 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 3, 2025 | CVE Modified | CVE |
| May 27, 2025 | Initial Analysis | [email protected] |
| May 14, 2025 | CVE Modified | CISA-ADP |
| May 12, 2025 | New CVE Received | [email protected] |