CVE-2025-31200

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 16, 2025
Updated: Apr 18, 2025
CWE ID 787

Summary

CVE-2025-31200 is a memory corruption vulnerability that Apple addressed by improving bounds checking in its handling of audio streams in certain media files. This issue, which can lead to code execution, was discovered in tvOS 18.4, visionOS 2.4, iOS 18.4.1, and iPadOS 18.4.1, as well as macOS Sequoia 15.4.1. A maliciously crafted media file can exploit this vulnerability, potentially resulting in a sophisticated attack against targeted individuals on iOS devices. The flaw has been patched in the latest software updates.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share