CVE-2025-31226: Apple iPadOS

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing a maliciously crafted image may lead to a denial-of-service.

Affected products

  • Apple iPadOS: before 17.7.7 (fixed in 17.7.7); from 18.0, before 18.5 (fixed in 18.5)
  • Apple iPhone OS: before 18.5 (fixed in 18.5)
  • Apple macOS: before 15.5 (fixed in 15.5)
  • Apple tvOS: before 18.5 (fixed in 18.5)
  • Apple visionOS: before 2.5 (fixed in 2.5)
  • Apple watchOS: before 11.5 (fixed in 11.5)

Published 2025-05-12. Last modified 2026-06-17.