CVE-2025-31229Weak Encoding for Password in Apple IOS AND Ipados

Severity
9.1CRITICALNVD
EPSS
0.1%
top 69.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 30

Description

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.6 and iPadOS 18.6. Passcode may be read aloud by VoiceOver.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 3.9 | Impact: 5.2

Affected Packages3 packages

NVDapple/ipados< 18.6
CVEListV5apple/ios_and_ipados< 18.6
NVDapple/iphone_os< 18.6

🔴Vulnerability Details

2
GHSA
GHSA-v3q5-xfqm-wpf2: A logic issue was addressed with improved checks2025-07-30
CVEList
CVE-2025-31229: A logic issue was addressed with improved checks2025-07-29

📋Vendor Advisories

1
Apple
CVE-2025-31229: iOS 18.6 and iPadOS 18.62025-07-29
CVE-2025-31229 — Weak Encoding for Password in Apple | cvebase