CVE-2025-31216
BaseFortify
Publication date: 2025-11-21
Last updated on: 2026-04-02
Assigner: Apple Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apple | ipados | to 17.7.7 (exc) |
| apple | ipados | From 18.0 (inc) to 18.5 (exc) |
| apple | iphone_os | to 18.5 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability allows an attacker with physical access to an Apple device running iPadOS or iOS to override managed Wi-Fi profiles. It was addressed by improved checks and fixed in iPadOS 17.7.7, iOS 18.5, and iPadOS 18.5.
How can this vulnerability impact me? :
If exploited, this vulnerability could allow an attacker with physical access to your device to override managed Wi-Fi profiles, potentially leading to unauthorized network connections or bypassing network restrictions.
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, update your device to iPadOS 17.7.7, iOS 18.5, or iPadOS 18.5 as these versions include the fix with improved checks to prevent an attacker with physical access from overriding managed Wi-Fi profiles.