CVE-2025-31220: Apple iPadOS

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

A privacy issue was addressed by removing sensitive data. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. A malicious app may be able to read sensitive location information.

Affected products

  • Apple iPadOS: before 17.7.7 (fixed in 17.7.7)
  • Apple macOS: before 13.7.6 (fixed in 13.7.6); from 14.0, before 14.7.6 (fixed in 14.7.6); from 15.0, before 15.5 (fixed in 15.5)

Published 2025-05-12. Last modified 2026-06-17.