
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-31255 is an improper authorization vulnerability in Apple's IOKit framework that allows a malicious app to access sensitive user data. The flaw stems from an authorization issue addressed with improved state management. It affects iOS and iPadOS (before version 26), macOS Sonoma (before 14.8), macOS Sequoia (before 15.7), macOS Tahoe 26, tvOS (before version 26), and watchOS (before version 26). Apple disclosed and patched the vulnerability on September 15, 2025. Feedly assigns a CVSS v3.1 base score of 9.8 (Critical), though Apple's own advisory does not publish a CVSS score (Apple Advisory iOS 26, Apple Advisory macOS Sonoma, Apple Advisory tvOS 26).
The vulnerability is classified as CWE-285 (Improper Authorization) and resides in Apple's IOKit subsystem, which provides the kernel-level framework for device driver communication across Apple operating systems. The root cause is improper state management during authorization checks, which can allow an app to bypass access controls and read sensitive user data that it should not be permitted to access. The vulnerability was discovered and reported by Csaba Fitzl (@theevilbit) of Kandji. No public technical write-up or proof-of-concept code has been identified at this time (Apple Advisory iOS 26, Apple Advisory macOS Sonoma, Apple Advisory watchOS 26).
Successful exploitation allows a malicious app installed on an affected device to access sensitive user data without proper authorization, impacting confidentiality. The vulnerability affects a broad range of Apple platforms — iOS, iPadOS, macOS (Sonoma and Sequoia), macOS Tahoe, tvOS, and watchOS — meaning the potential attack surface spans iPhones, iPads, Macs, Apple TVs, and Apple Watches. While the primary impact is unauthorized data access (high confidentiality impact), the Feedly-assigned CVSS score also indicates high integrity and availability impact, suggesting the flaw could be leveraged as part of a broader attack chain (Apple Advisory iOS 26, Apple Advisory macOS Tahoe).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The vulnerability has an EPSS score of approximately 0.024%, indicating a low current probability of exploitation in the wild. CVE-2025-31255 has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a malicious app to be installed on the target device, which limits the attack surface compared to fully remote, zero-click vulnerabilities.
Apple has released patches for all affected platforms. Users should update to the following versions or later: iOS 26 and iPadOS 26, macOS Sonoma 14.8, macOS Sequoia 15.7, macOS Tahoe 26, tvOS 26, and watchOS 26. No configuration-based workarounds have been published by Apple. As a precautionary measure, users should review installed app permissions, avoid sideloading applications from untrusted sources, and only install apps from the official App Store or trusted enterprise sources (Apple Advisory iOS 26, Apple Advisory macOS Sonoma, Apple Advisory macOS Tahoe).
The vulnerability was noted in security community aggregators such as SANS Internet Storm Center and FullDisclosure mailing lists shortly after Apple's September 15, 2025 disclosure, as part of broader coverage of Apple's September 2025 security update batch. No specific high-profile researcher commentary or significant social media discussion focused exclusively on CVE-2025-31255 has been identified, as it was disclosed alongside numerous other vulnerabilities in the same update cycle (SANS ISC, FullDisclosure).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."