CVE-2025-31246: Apple macOS
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6. Connecting to a malicious AFP server may corrupt kernel memory.
Affected products
- Apple macOS: before 14.7.6 (fixed in 14.7.6); from 15.0, before 15.5 (fixed in 15.5)
Published 2025-05-12. Last modified 2026-06-17.