CVE-2025-31201: Apple Multiple Products Arbitrary Read and Write Vulnerability
Apple iOS, iPadOS, macOS, and other Apple products contain an arbitrary read and write vulnerability that allows an attacker to bypass Pointer Authentication.
Other sources
CoreAudio. A memory corruption issue was addressed with improved bounds checking.
— Apple
RPAC. This issue was addressed by removing the vulnerable code.
— Apple
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.
— MITRE
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 18.4.1 - Upgrade
Upgrade
macOSto a version that resolves this vulnerability.Fixed in 15.4.1 - Upgrade
Upgrade
visionOSto a version that resolves this vulnerability.Fixed in 2.4.1 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 18.4.1 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 18.4.1 - Compensating control
Apply mitigations per vendor (Apple) instructions; follow applicable BOD 22-01 guidance for cloud services; discontinue use of the product if mitigations are unavailable.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2025-31201?
CVE-2025-31201 is considered a high severity vulnerability due to its memory corruption issue.
How do I fix CVE-2025-31201?
To fix CVE-2025-31201, update your device to macOS Sequoia 15.4.1, visionOS 2.4.1, or iOS/iPadOS/tvOS 18.4.1.
What types of devices are affected by CVE-2025-31201?
CVE-2025-31201 affects devices running macOS Sequoia, iOS, iPadOS, tvOS, and visionOS before the specified updates.
Is there a specific patch for CVE-2025-31201?
Yes, CVE-2025-31201 is patched in the latest updates: macOS Sequoia 15.4.1, visionOS 2.4.1, and iOS/iPadOS/tvOS 18.4.1.
What is the nature of the vulnerability in CVE-2025-31201?
CVE-2025-31201 involves a memory corruption issue in CoreAudio that was addressed with improved bounds checking.