An authentication issue was addressed with improved state management. This issue is fixed in App Store Connect 3.0. An attacker with physical access to an unlocked device may be able to view sensitive user information.
References
History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00026}

epss

{'score': 0.00023}


Tue, 15 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00026}


Thu, 10 Jul 2025 22:30:00 +0000

Type Values Removed Values Added
Description An authentication issue was addressed with improved state management. This issue is fixed in App Store Connect 3.0. An attacker with physical access to an unlocked device may be able to view sensitive user information.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published: 2025-07-10T22:23:29.784Z

Updated: 2025-07-15T13:45:00.820Z

Reserved: 2025-03-27T16:13:58.341Z

Link: CVE-2025-31267

cve-icon Vulnrichment

Updated: 2025-07-15T13:44:55.984Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-10T23:15:27.800

Modified: 2025-07-15T14:15:27.973

Link: CVE-2025-31267

cve-icon Redhat

No data.