cbcvebase.
CVE-2025-31200
published 2025-04-16

CVE-2025-31200: A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1…

PriorityP191critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-05-08
Exploited in the wild
EPSS
21.92%
97.4th percentile
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1, watchOS 11.5. Processing an audio stream in a maliciously crafted media file may result in code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS released before iOS 18.4.1.

Affected

13 ranges
VendorProductVersion rangeFixed in
appleios_18.4.1_and_ipados
appleios_and_ipados< 18.4.118.4.1
appleipados< 18.4.118.4.1
appleiphone_os< 18.4.118.4.1
applemacos< 15.4.115.4.1
applemacos>= 15.0 < 15.4.115.4.1
applemacos_sequoia
appletvos< 18.4.118.4.1
appletvos
applevisionos< 2.4.12.4.1
applevisionos
applewatchos< 11.511.5
applewatchos

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2025-31200 is a CoreAudio memory corruption (out-of-bounds write) triggered by processing an audio stream inside a maliciously crafted media file — monitor for unexpected media file parsing activity in CoreAudio on Apple devices, especially from untrusted sources.
  • The vulnerability resides in the CoreAudio component; detection should focus on CoreAudio process anomalies (unexpected child processes, memory violations) when handling media files on iOS, iPadOS, macOS, tvOS, visionOS, and watchOS.
  • This zero-day was exploited in the wild in highly targeted, sophisticated attacks against specific individuals on iOS versions prior to 18.4.1 — treat any unpatched Apple device (iOS < 18.4.1, macOS < 15.4.1, tvOS < 18.4.1, visionOS < 2.4.1, watchOS < 11.5) as high-risk and prioritize patching.
  • CVE-2025-31200 was frequently chained with CVE-2025-31201 (RPAC Pointer Authentication bypass); detections should consider both vulnerabilities being exploited together as part of a multi-stage attack chain.
  • ·Apple has not publicly disclosed technical details, samples, or infrastructure used in the attacks; no hashes, domains, IPs, or specific malicious file names are available from the sources.
  • ·Exploitation has only been confirmed against specific targeted individuals on iOS versions before 18.4.1; broader exploitation scope is not confirmed, limiting the ability to build high-confidence network-based IOCs.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.