← back
CVE-2025-31264

CVE-2025-31264

CVSS 4.6 MEDIUMEPSS 0.2%CWE-287
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.6EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
29 May 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker with physical access to a locked device may be able to view sensitive user information.
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
Apple · macOS