CVE-2025-31200
published 2025-04-16CVE-2025-31200: A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1…
PriorityP191critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-05-08
Exploited in the wild
EPSS
21.92%
97.4th percentile
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1, watchOS 11.5. Processing an audio stream in a maliciously crafted media file may result in code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS released before iOS 18.4.1.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_18.4.1_and_ipados | — | — |
| apple | ios_and_ipados | < 18.4.1 | 18.4.1 |
| apple | ipados | < 18.4.1 | 18.4.1 |
| apple | iphone_os | < 18.4.1 | 18.4.1 |
| apple | macos | < 15.4.1 | 15.4.1 |
| apple | macos | >= 15.0 < 15.4.1 | 15.4.1 |
| apple | macos_sequoia | — | — |
| apple | tvos | < 18.4.1 | 18.4.1 |
| apple | tvos | — | — |
| apple | visionos | < 2.4.1 | 2.4.1 |
| apple | visionos | — | — |
| apple | watchos | < 11.5 | 11.5 |
| apple | watchos | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2025-31200 is a CoreAudio memory corruption (out-of-bounds write) triggered by processing an audio stream inside a maliciously crafted media file — monitor for unexpected media file parsing activity in CoreAudio on Apple devices, especially from untrusted sources. ↗
- →The vulnerability resides in the CoreAudio component; detection should focus on CoreAudio process anomalies (unexpected child processes, memory violations) when handling media files on iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. ↗
- →This zero-day was exploited in the wild in highly targeted, sophisticated attacks against specific individuals on iOS versions prior to 18.4.1 — treat any unpatched Apple device (iOS < 18.4.1, macOS < 15.4.1, tvOS < 18.4.1, visionOS < 2.4.1, watchOS < 11.5) as high-risk and prioritize patching. ↗
- →CVE-2025-31200 was frequently chained with CVE-2025-31201 (RPAC Pointer Authentication bypass); detections should consider both vulnerabilities being exploited together as part of a multi-stage attack chain. ↗
- ·Apple has not publicly disclosed technical details, samples, or infrastructure used in the attacks; no hashes, domains, IPs, or specific malicious file names are available from the sources. ↗
- ·Exploitation has only been confirmed against specific targeted individuals on iOS versions before 18.4.1; broader exploitation scope is not confirmed, limiting the ability to build high-confidence network-based IOCs. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2025-31200: watchOS 11.5
vendor_apple·2025-05-12·CVSS 9.8
CVE-2025-31200 [CRITICAL] CVE-2025-31200: watchOS 11.5
Apple Security Update: About the security content of watchOS 11.5
Product: watchOS
Version: 11.5
CVE: CVE-2025-31200
Component: CoreAudio
Impact: Processing an audio stream in a maliciously crafted media file may result in code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS released before iOS 18.4.1.
Description: A memory corruption issue was addressed with improved bounds checking.
CISA
Apple Multiple Products Memory Corruption Vulnerability
cisa·2025-04-17·CVSS 9.8
CVE-2025-31200 [CRITICAL] Apple Multiple Products Memory Corruption Vulnerability
Vulnerability: Apple Multiple Products Memory Corruption Vulnerability
Affected: Apple Multiple Products
Apple iOS, iPadOS, macOS, and other Apple products contain a memory corruption vulnerability that allows for code execution when processing an audio stream in a maliciously crafted media file.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://support.apple.com/en-us/122282 ; https://support.apple.com/en-us/122400 ; https://support.apple.com/en-us/122401 ; https://support.apple.com/en-us/122402 ; https://nvd.nist.gov/vuln/detail/CVE-2025-31200
Remediation Due Date: 2025-05-08
Apple
CVE-2025-31200: tvOS 18.4.1
vendor_apple·2025-04-16·CVSS 9.8
CVE-2025-31200 [CRITICAL] CVE-2025-31200: tvOS 18.4.1
Apple Security Update: About the security content of tvOS 18.4.1
Product: tvOS
Version: 18.4.1
CVE: CVE-2025-31200
Component: CoreAudio
Impact: Processing an audio stream in a maliciously crafted media file may result in code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.
Description: A memory corruption issue was addressed with improved bounds checking.
Apple
CVE-2025-31200: visionOS 2.4.1
vendor_apple·2025-04-16·CVSS 9.8
CVE-2025-31200 [CRITICAL] CVE-2025-31200: visionOS 2.4.1
Apple Security Update: About the security content of visionOS 2.4.1
Product: visionOS
Version: 2.4.1
CVE: CVE-2025-31200
Component: CoreAudio
Impact: Processing an audio stream in a maliciously crafted media file may result in code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.
Description: A memory corruption issue was addressed with improved bounds checking.
Apple
CVE-2025-31200: iOS 18.4.1 and iPadOS 18.4.1
vendor_apple·2025-04-16·CVSS 9.8
CVE-2025-31200 [CRITICAL] CVE-2025-31200: iOS 18.4.1 and iPadOS 18.4.1
Apple Security Update: About the security content of iOS 18.4.1 and iPadOS 18.4.1
Product: iOS 18.4.1 and iPadOS
Version: 18.4.1
CVE: CVE-2025-31200
Component: CoreAudio
Impact: Processing an audio stream in a maliciously crafted media file may result in code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.
Description: A memory corruption issue was addressed with improved bounds checking.
Apple
CVE-2025-31200: macOS Sequoia 15.4.1
vendor_apple·2025-04-16·CVSS 9.8
CVE-2025-31200 [CRITICAL] CVE-2025-31200: macOS Sequoia 15.4.1
Apple Security Update: About the security content of macOS Sequoia 15.4.1
Product: macOS Sequoia
Version: 15.4.1
CVE: CVE-2025-31200
Component: CoreAudio
Impact: Processing an audio stream in a maliciously crafted media file may result in code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.
Description: A memory corruption issue was addressed with improved bounds checking.
GHSA
GHSA-8f6m-fvf9-6397: A memory corruption issue was addressed with improved bounds checking
ghsa_unreviewed·2025-04-16
CVE-2025-31200 [HIGH] CWE-119 GHSA-8f6m-fvf9-6397: A memory corruption issue was addressed with improved bounds checking
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in tvOS 18.4.1, visionOS 2.4.1, iOS iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1. Processing an audio stream in a maliciously crafted media file may result in code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.
VulnCheck
Apple Multiple Products Memory Corruption Vulnerability
vulncheck·2025·CVSS 9.8
CVE-2025-31200 [CRITICAL] Apple Multiple Products Memory Corruption Vulnerability
Apple Multiple Products Memory Corruption Vulnerability
Apple iOS, iPadOS, macOS, and other Apple products contain a memory corruption vulnerability that allows for code execution when processing an audio stream in a maliciously crafted media file.
Affected: Apple Multiple Products
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://isc.sans.edu/diary/Apple%20Patches%20Exploited%20Vulnerability/31866; https://support.apple.com/en-us/122282; https://support.apple.com/en-us/122400; https://support.apple.com/en-us/122401; https://support.a
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Apple fixes two zero-day flaws exploited in 'sophisticated' attacks
blogs_bleepingcomputer·2025-12-12·CVSS 8.8
CVE-2025-43529 [HIGH] Apple fixes two zero-day flaws exploited in 'sophisticated' attacks
## Apple fixes two zero-day flaws exploited in 'sophisticated' attacks
## Lawrence Abrams
CVE-2025-43529 is a WebKit use-after-free remote code execution flaw that can be exploited by processing maliciously crafted web content. Apple says the flaw was discovered by Google’s Threat Analysis Group.
CVE-2025-14174 is a WebKit memory corruption flaw that could lead to memory corruption. Apple says the flaw was discovered by both Apple and Google’s Threat Analysis Group.
Devices impacted by both flaws include:
iPhone 11 and later
iPad Pro 12.9-inch (3rd generation and later)
iPad Pro 11-inch (1st generation and later)
iPad Air (3rd generation and later)
iPad (8th generation and later)
iPad mini (5th generation and later)
Apple has fixed the flaws in iOS 26.2 and iPadOS 26.2, iOS 18.7
Bleepingcomputer
Apple backports zero-day patches to older iPhones and iPads
blogs_bleepingcomputer·2025-09-16·CVSS 10.0
[CRITICAL] Apple backports zero-day patches to older iPhones and iPads
## Apple backports zero-day patches to older iPhones and iPads
## Sergiu Gatlan
An out-of-bounds write occurs when attackers supply maliciously crafted input to a program that causes it to write data outside the allocated memory buffer, potentially triggering crashes, corrupting data, or even allowing remote code execution.
Apple has now addressed this zero-day flaw in iOS 15.8.5 / 16.7.12, as well as iPadOS 15.8.5 / 16.7.12, with improved bounds checks.
"Processing a malicious image file may result in memory corruption. An out-of-bounds write issue was addressed with improved bounds checking," the company said in Monday advisories .
"Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals."
The lis
Bleepingcomputer
Apple fixes new zero-day flaw exploited in targeted attacks
blogs_bleepingcomputer·2025-08-20·CVSS 10.0
[CRITICAL] Apple fixes new zero-day flaw exploited in targeted attacks
## Apple fixes new zero-day flaw exploited in targeted attacks
## Sergiu Gatlan
"Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals," the company revealed in security advisories issued on Wednesday.
"An out-of-bounds write issue was addressed with improved bounds checking. Processing a malicious image file may result in memory corruption."
Apple has addressed this issue with improved bounds checking to prevent exploitation in iOS 18.6.2 and iPadOS 18.6.2 , iPadOS 17.7.10 , macOS Sequoia 15.6.1 , macOS Sonoma 14.7.8 , and macOS Ventura 13.7.8 .
The complete list of devices impacted by this zero-day vulnerability is extensive, as the bug impacts both older and newer models, including:
iPhone XS a
Bleepingcomputer
Apple patches security flaw exploited in Chrome zero-day attacks
blogs_bleepingcomputer·2025-07-30·CVSS 8.8
CVE-2025-6558 [HIGH] Apple patches security flaw exploited in Chrome zero-day attacks
## Apple patches security flaw exploited in Chrome zero-day attacks
## Sergiu Gatlan
Vlad Stolyarov and Clément Lecigne of Google's Threat Analysis Group (TAG), a team of security experts dedicated to defending Google customers against state-sponsored attacks, discovered CVE-2025-6558 in June and reported it to the Google Chrome team, who patched it on July 15 and tagged it as actively exploited in attacks.
While Google has yet to provide further information on these attacks, Google TAG frequently discovers zero-day flaws exploited by government-sponsored threat actors in targeted campaigns aimed at deploying spyware on devices of high-risk individuals, including dissidents, opposition politicians, and journalists.
On Tuesday, Apple released WebKit security updates to address the CVE-2
Checkpoint
21st April – Threat Intelligence Report
blogs_checkpoint·2025-04-21
CVE-2025-24054 21st April – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 21st April – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 21st April, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Retail giant Ahold Delhaize has suffered a cyber-attack resulting in data theft of customer information from its US business systems. The attack, claimed by ransomware group INC Ransom, impacted Ahold Delhaize USA brands and services including e-commerce operations and pharmacies.
Check Point Threat Emulation provides protec
Bleepingcomputer
Apple fixes two zero-days exploited in targeted iPhone attacks
blogs_bleepingcomputer·2025-04-16·CVSS 10.0
CVE-2025-31200 [CRITICAL] Apple fixes two zero-days exploited in targeted iPhone attacks
## Apple fixes two zero-days exploited in targeted iPhone attacks
## Lawrence Abrams
The CVE-2025-31200 flaw in CoreAudio was discovered by Apple and the Google Threat Analysis team. It can be exploited by processing an audio stream in a maliciously crafted media file to execute remote code on the device.
The company also fixed CVE-2025-31201, which Apple discovered. It is a bug in RPAC that allows attackers with read or write access to bypass Pointer Authentication (PAC), an iOS security feature that helps protect against memory vulnerabilities.
Apple has not shared further details on how the flaws were exploited in attacks. BleepingComputer contacted Apple and Google with questions about flaws but has not received a response.
Both vulnerabilities were fixed in iOS 18.4.1 , iPadOS 18
https://support.apple.com/en-us/122282https://support.apple.com/en-us/122400https://support.apple.com/en-us/122401https://support.apple.com/en-us/122402https://support.apple.com/en-us/122722http://seclists.org/fulldisclosure/2025/Apr/26http://seclists.org/fulldisclosure/2025/Jun/14http://seclists.org/fulldisclosure/2025/May/10http://seclists.org/fulldisclosure/2025/Oct/0http://seclists.org/fulldisclosure/2025/Oct/4https://blog.noahhw.dev/posts/cve-2025-31200/https://news.ycombinator.com/item?id=44161894https://github.com/JGoyd/iOS-Attack-Chain-CVE-2025-31200-CVE-2025-31201/blob/main/Remote%20Crypto%20Attack%20Chain%20.mdhttps://github.com/cisagov/vulnrichment/issues/200https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-31200
2025-04-16
Published
2025-04-17
Added to CISA KEV
Exploited in the wild