CRITICAL🇵🇱 Wersja polska

CVE-2025-31229

CVSS 9.1v3.1pub. 2025-07-30upd. 2025-11-03

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.6 and iPadOS 18.6. Passcode may be read aloud by VoiceOver.

🤖 AI Analysis
How it works

In iOS and iPadOS systems before version 18.6, a logic error (CWE-261) was discovered consisting of improper storage or handling of the screen lock code. The VoiceOver accessibility feature, designed to assist visually impaired persons, could read the passcode aloud under certain conditions. Apple indicates that the problem was fixed by introducing improved verification mechanisms.

Impact

An attacker or person in the vicinity of the device can hear the screen lock code read aloud by VoiceOver, enabling unauthorized access to the device and data stored on it.

Mitigation & patch

Devices should be updated to iOS 18.6 and iPadOS 18.6, in which Apple has implemented a fix eliminating this issue. Detailed information is available on the Apple support page: https://support.apple.com/en-us/124147

Who is affected

Apple iOS before version 18.6 and Apple iPadOS before version 18.6

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
  • Apple iPadOS

    OS
    Apple
    < 18.6
  • Apple iOS

    OS
    Apple
    < 18.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-43300CRITICAL10.0⚠ KEVPL ✓same product

Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu

CVE-2025-31200CRITICAL9.8⚠ KEVPL ✓same product

Apple — memory corruption (RCE) w przetwarzaniu strumieni audio

CVE-2025-31201CRITICAL9.8⚠ KEVPL ✓same product

Apple: Obejście Pointer Authentication w iOS, macOS i innych platformach

CVE-2025-24201CRITICAL10.0⚠ KEVPL ✓same product

Apple WebKit: out-of-bounds write umożliwiający ucieczkę z sandbox przeglądarki

CVE-2025-24085CRITICAL10.0⚠ KEVPL ✓same product

Use-after-free w Apple iOS/iPadOS/macOS — privilege escalation przez aplikację