CVE-2025-31246
published 2025-05-12CVE-2025-31246: The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6. Connecting to a malicious AFP server may…
PriorityP344high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.48%
38.5th percentile
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6. Connecting to a malicious AFP server may corrupt kernel memory.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 15.5 | 15.5 |
| apple | macos | < 14.7.6 | 14.7.6 |
| apple | macos | >= 15.0 < 15.5 | 15.5 |
| apple | macos_sequoia | — | — |
| apple | macos_sonoma | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GPT-Pilot contains a command injection vulnerability in the Executor.run() method
ghsa·2026-05-11
CVE-2026-31246 [MEDIUM] CWE-78 GPT-Pilot contains a command injection vulnerability in the Executor.run() method
GPT-Pilot contains a command injection vulnerability in the Executor.run() method
GPT-Pilot thru commit 0819827ce20346ef5f25b3fe29293cb448840565 (2025-09-03) contains a command injection vulnerability (CWE-78) in the Executor.run() method. During project execution, when the system prompts the user to confirm or modify a command to be run, it accepts free-text input without proper validation. The user-supplied input is directly passed to asyncio.create_subprocess_shell() for execution. This allows an attacker to replace the intended command with arbitrary shell commands, leading to remote code execution with the privileges of the GPT-Pilot process.
GHSA
GHSA-5f3f-773x-9jx9: The issue was addressed with improved memory handling
ghsa_unreviewed·2025-05-13
CVE-2025-31246 [HIGH] CWE-119 GHSA-5f3f-773x-9jx9: The issue was addressed with improved memory handling
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6. Connecting to a malicious AFP server may corrupt kernel memory.
Apple
CVE-2025-31246: macOS Sequoia 15.5
vendor_apple·2025-05-12·CVSS 8.8
CVE-2025-31246 [HIGH] CVE-2025-31246: macOS Sequoia 15.5
Apple Security Update: About the security content of macOS Sequoia 15.5
Product: macOS Sequoia
Version: 15.5
CVE: CVE-2025-31246
Component: About Apple security updates
Impact: Connecting to a malicious AFP server may corrupt kernel memory
Description: The issue was addressed with improved memory handling.
Apple
CVE-2025-31246: macOS Sonoma 14.7.6
vendor_apple·2025-05-12·CVSS 8.8
CVE-2025-31246 [HIGH] CVE-2025-31246: macOS Sonoma 14.7.6
Apple Security Update: About the security content of macOS Sonoma 14.7.6
Product: macOS Sonoma
Version: 14.7.6
CVE: CVE-2025-31246
Component: About Apple security updates
Impact: Connecting to a malicious AFP server may corrupt kernel memory
Description: The issue was addressed with improved memory handling.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-05-12
Published