Description
This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. Mounting a maliciously crafted AFP network share may lead to system termination.
Published: 2025-05-12
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (System Crash)
Action: Immediate Patch
AI Analysis

Impact

A maliciously crafted Apple File Protocol share can cause the operating system to terminate abruptly. The flaw is a failure to validate input received from an AFP connection, allowing an attacker to trigger a crash. The resulting impact is a loss of service rather than data exposure or code execution. The weakness is classified as CWE‑20, reflecting a lack of proper input validation.

Affected Systems

Apple macOS systems are affected. The vulnerability exists until the releases that contain the fix: macOS Sequoia 15.5, macOS Sonoma 14.7.6, and macOS Ventura 13.7.6. Earlier macOS releases lack the improved checks and remain vulnerable.

Risk and Exploitability

The CVSS score is 7.5, indicating a high severity denial of service risk. The EPSS score is below 1%, signaling a low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this weakness from a network that can reach an AFP share, making the vector remote. Because the flaw lies in input validation, it typically requires only network access to an AFP server and does not demand elevated privileges.

Generated by OpenCVE AI on April 28, 2026 at 01:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade macOS to a version that includes the fix (Sequoia 15.5, Sonoma 14.7.6, or Ventura 13.7.6).
  • Enable automatic system updates so that future patches addressing this issue or related AFP bugs are applied promptly.
  • If immediate update is not possible, disable or restrict AFP access on the network until the operating system is updated, or use a firewall to block unauthorized AFP connections.

Generated by OpenCVE AI on April 28, 2026 at 01:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-14625 This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. Mounting a maliciously crafted AFP network share may lead to system termination.
History

Tue, 28 Apr 2026 02:00:00 +0000

Type Values Removed Values Added
Title AFP Share Malicious Crafting Triggers System Crash on macOS

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. Mounting a maliciously crafted AFP network share may lead to system termination. This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. Mounting a maliciously crafted AFP network share may lead to system termination.

Mon, 03 Nov 2025 20:30:00 +0000


Tue, 27 May 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos

Tue, 13 May 2025 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 12 May 2025 21:45:00 +0000

Type Values Removed Values Added
Description This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. Mounting a maliciously crafted AFP network share may lead to system termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:24:21.229Z

Reserved: 2025-03-27T16:13:58.325Z

Link: CVE-2025-31240

cve-icon Vulnrichment

Updated: 2025-11-03T19:51:32.295Z

cve-icon NVD

Status : Modified

Published: 2025-05-12T22:15:24.367

Modified: 2026-04-02T19:19:53.300

Link: CVE-2025-31240

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T01:45:18Z

Weaknesses