CVE-2025-31200: Apple Multiple Products Memory Corruption Vulnerability
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1, watchOS 11.5. Processing an audio stream in a maliciously crafted media file may result in code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS released before iOS 18.4.1.
Other sources
Apple iOS, iPadOS, macOS, and other Apple products contain a memory corruption vulnerability that allows for code execution when processing an audio stream in a maliciously crafted media file.
— CISA
AppleJPEG. The issue was addressed with improved input sanitization.
— Apple
Core Bluetooth. This issue was addressed through improved state management.
— Apple
CoreAudio. A memory corruption issue was addressed with improved bounds checking.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 18.4.1 - Upgrade
Upgrade
macOSto a version that resolves this vulnerability.Fixed in 15.4.1 - Upgrade
Upgrade
visionOSto a version that resolves this vulnerability.Fixed in 2.4.1 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 18.4.1 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 18.4.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.5 - Upgrade
Upgrade
Apple iOSto a version that resolves this vulnerability.Fixed in 18.4.1 - Upgrade
Upgrade
Apple iPadOSto a version that resolves this vulnerability.Fixed in 18.4.1 - Upgrade
Upgrade
watchOSto a version that resolves this vulnerability.Fixed in 11.5 - Compensating control
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-31200
- CVE-2025-31201
- CVE-2025-31251
- CVE-2025-31212
- CVE-2025-31208
- CVE-2025-31209
- CVE-2025-31239
- CVE-2025-31233
- CVE-2025-31226
- CVE-2025-24224
- CVE-2025-31219
- CVE-2025-31241
- CVE-2024-8176
- CVE-2025-31222
- CVE-2025-31221
- CVE-2025-31242
- CVE-2025-24213
- CVE-2025-31223
- CVE-2025-31238
- CVE-2025-24223
- CVE-2025-31204
- CVE-2025-31217
- CVE-2025-31215
- CVE-2025-31206
- CVE-2025-31205
- CVE-2025-31257
- CVE-2025-43374
Frequently Asked Questions
What is the severity of CVE-2025-31200?
CVE-2025-31200 is a critical memory corruption vulnerability that can lead to code execution when processing malicious audio streams.
How do I fix CVE-2025-31200?
CVE-2025-31200 can be fixed by updating to the latest versions of affected software: tvOS 18.4.1, visionOS 2.4.1, iOS 18.4.1, iPadOS 18.4.1, and macOS Sequoia 15.4.1.
What products are affected by CVE-2025-31200?
CVE-2025-31200 affects Apple products that include tvOS, visionOS, iOS, iPadOS, and macOS Sequoia.
What types of attacks can exploit CVE-2025-31200?
CVE-2025-31200 can be exploited through specially crafted media files that target memory corruption vulnerabilities.
What should users do if they are vulnerable to CVE-2025-31200?
Users vulnerable to CVE-2025-31200 should immediately update their devices to the latest available software versions provided by Apple.