CVE-2025-31201

CVSS 3.1 Score 6.8 of 10 (medium)

Details

Published Apr 16, 2025
Updated: Apr 18, 2025
CWE ID 287

Summary

CVE-2025-31201 is a vulnerability that affected multiple Apple operating systems, including tvOS, visionOS, iOS, iPadOS, and macOS. The issue was caused by vulnerable code that has since been removed. This vulnerability allowed an attacker with arbitrary read and write capabilities to potentially bypass Pointer Authentication. Apple released patches for the issue in tvOS 18.4.1, visionOS 2.4.1, iOS 18.4.1, and iPadOS 18.4.1, as well as macOS Sequoia 15.4.1. It is reported that this vulnerability may have been exploited in targeted attacks against specific individuals on iOS.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share