An authentication issue was addressed with improved state management. This issue is fixed in App Store Connect 3.0. An attacker with physical access to an unlocked device may be able to view sensitive user information.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://support.apple.com/en-us/123356 |
|
History
Tue, 29 Jul 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple app Store Connect |
|
| CPEs | cpe:2.3:a:apple:app_store_connect:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apple
Apple app Store Connect |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 15 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-287 | |
| Metrics |
cvssV3_1
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
Thu, 10 Jul 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authentication issue was addressed with improved state management. This issue is fixed in App Store Connect 3.0. An attacker with physical access to an unlocked device may be able to view sensitive user information. | |
| References |
|
Status: PUBLISHED
Assigner: apple
Published: 2025-07-10T22:23:29.784Z
Updated: 2025-07-15T13:45:00.820Z
Reserved: 2025-03-27T16:13:58.341Z
Link: CVE-2025-31267
Updated: 2025-07-15T13:44:55.984Z
Status : Analyzed
Published: 2025-07-10T23:15:27.800
Modified: 2025-07-29T18:08:30.433
Link: CVE-2025-31267
No data.
ReportizFlow