CVE-2025-31207Patch(apple / ipados)

MEDIUMCVSS 7.7 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. An app may be able to enumerate a user's installed apps.

4.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-200

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-03-25); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
ipadosiphone_os

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-25: 1Mentions · 2026-08-04: 1Active Exploitation · 2026-03-25: 1Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-08-04: 1Technical Details · 2026-03-25: 103-2508-04
Signal classification1 categories
Patch
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • icraze@icrazeios
    Patch

    I’ve just released AppEnumFix on my repo It’s a tweak to patch CVE-2025-31207, a bug that allows sandboxed applications to enumerate a user's installed apps It has been exploited by some App Store apps to detect whether TrollStore has been installed on the device

    Post summary

    The author released the AppEnumFix tweak to patch CVE-2025-31207, an enumeration flaw now actively exploited by some App Store apps.

    390105198.2K
    11.7K followersView on X
  • ONE Jailbreak@onejailbreak_
    Patch

    🗞️AppEnumGuard Tweak Closes CVE-2025-31207 Bug on Relaxin Jailbreak and iOS 17🩹 https://onejailbreak.com/blog/appenumguard-mitigates-cve-2025-31207-relaxin/

    Post summary

    The AppEnumGuard tweak provides a fix for CVE-2025-31207 on Relaxin jailbreak and iOS 17, offering a direct mitigation rather than a PoC or exploit.

    140591719.7K
    34.2K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---

Explore more