CVE-2025-31200
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Apr 16, 2025
Updated: Apr 18, 2025
CWE ID 787
Summary
CVE-2025-31200 is a memory corruption vulnerability that Apple addressed by improving bounds checking in its handling of audio streams in certain media files. This issue, which can lead to code execution, was discovered in tvOS 18.4, visionOS 2.4, iOS 18.4.1, and iPadOS 18.4.1, as well as macOS Sequoia 15.4.1. A maliciously crafted media file can exploit this vulnerability, potentially resulting in a sophisticated attack against targeted individuals on iOS devices. The flaw has been patched in the latest software updates.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.