CVE-2025-31276

This issue was addressed through improved state management. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9. Remote content may be loaded even when the 'Load Remote Images' setting is turned off.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

History

03 Nov 2025, 20:18

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2025/Jul/31 -

Information

Published : 2025-07-30 00:15

Updated : 2025-11-03 20:18


NVD link : CVE-2025-31276

Mitre link : CVE-2025-31276

CVE.ORG link : CVE-2025-31276


JSON object : View

Products Affected

apple

  • iphone_os
  • ipados
CWE
CWE-359

Exposure of Private Personal Information to an Unauthorized Actor