CVE-2025-31220
Description
A privacy issue was addressed by removing sensitive data. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. A malicious app may be able to read sensitive location information.
CWE
- CWE-200 — CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Affected
- Apple / iPadOS — v=0 <17.7.7 [affected]
- Apple / macOS — v=0 <13.7.6 [affected]; v=0 <14.7.6 [affected]; v=0 <15.5 [affected]
CVSS
- (none)
References
- https://support.apple.com/en-us/122405
- https://support.apple.com/en-us/122716
- https://support.apple.com/en-us/122717
- https://support.apple.com/en-us/122718
Source
cvelistV5-main/cves/2025/31xxx/CVE-2025-31220.json