cbcvebase.
CVE-2025-31201
published 2025-04-16

CVE-2025-31201: This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS…

PriorityP187critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-05-08
Exploited in the wild
EPSS
12.76%
95.8th percentile
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.

Affected

11 ranges
VendorProductVersion rangeFixed in
appleios_18.4.1_and_ipados
appleios_and_ipados< 18.4.118.4.1
appleipados< 18.4.118.4.1
appleiphone_os< 18.4.118.4.1
applemacos< 15.4.115.4.1
applemacos>= 15.0 < 15.4.115.4.1
applemacos_sequoia
appletvos< 18.4.118.4.1
appletvos
applevisionos< 2.4.12.4.1
applevisionos

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2025-31201 resides in the RPAC component; monitor for exploitation attempts targeting Pointer Authentication Code (PAC) bypass on iOS/iPadOS/macOS/tvOS/visionOS devices running versions prior to 18.4.1 / 15.4.1 / 2.4.1
  • The vulnerability requires an attacker to already possess arbitrary read and write capability as a precondition; detections should look for chained exploitation where a memory-corruption primitive (e.g. from CVE-2025-31200 CoreAudio) is followed by PAC bypass activity
  • CVE-2025-31201 was observed exploited in the wild alongside CVE-2025-31200 (CoreAudio malicious media file); treat both CVEs as part of a chained attack and correlate alerts for both components together
  • Apple's fix was removal of the vulnerable RPAC code entirely (not a bounds/logic patch); unpatched devices on iOS/iPadOS < 18.4.1, macOS Sequoia < 15.4.1, tvOS < 18.4.1, visionOS < 2.4.1 remain exposed and should be flagged in asset inventory
  • CISA KEV lists remediation due date 2025-05-08; use MDM/EDR telemetry to confirm patch compliance across all affected Apple product lines (iOS, iPadOS, macOS, tvOS, visionOS)
  • ·Exploitation has only been observed in highly targeted, sophisticated attacks against specific individuals on iOS; broad/opportunistic exploitation has not been reported
  • ·No technical details about the attack chain, threat actor, or delivery mechanism have been publicly disclosed by Apple or Google
  • ·The vulnerability is in the RPAC component and requires a pre-existing arbitrary read/write primitive; it is not independently exploitable without a companion memory-corruption vulnerability

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.