The issue was addressed with improved authentication. This issue is fixed in iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5. An attacker with physical access to a device may be able to access notes from the lock screen.
History

Tue, 13 May 2025 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 12 May 2025 21:45:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved authentication. This issue is fixed in iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5. An attacker with physical access to a device may be able to access notes from the lock screen.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published: 2025-05-12T21:42:37.095Z

Updated: 2025-05-13T19:42:11.798Z

Reserved: 2025-03-27T16:13:58.322Z

Link: CVE-2025-31228

cve-icon Vulnrichment

Updated: 2025-05-13T19:41:28.959Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-12T22:15:23.493

Modified: 2025-05-13T20:15:28.667

Link: CVE-2025-31228

cve-icon Redhat

No data.