CVE-2025-31279
BaseFortify
Publication date: 2025-07-30
Last updated on: 2026-04-02
Assigner: Apple Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apple | ipados | to 17.7.9 (exc) |
| apple | macos | to 13.7.7 (exc) |
| apple | macos | From 14.0 (inc) to 14.7.7 (exc) |
| apple | macos | From 15.0 (inc) to 15.6 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a permissions issue that could allow an app to fingerprint the user. Apple fixed it by adding additional restrictions to the permissions model to prevent unauthorized user fingerprinting. [1]
How can this vulnerability impact me? :
An app exploiting this vulnerability could potentially identify or track you by fingerprinting your device or user information without your consent, which may compromise your privacy. [1]
What immediate steps should I take to mitigate this vulnerability?
Update your Apple devices to the fixed versions: macOS Sequoia 15.6, iPadOS 17.7.9, macOS Sonoma 14.7.7, or macOS Ventura 13.7.7. These updates include additional restrictions to the permissions model that prevent unauthorized user fingerprinting. [1]