Vulnerability Description
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Macos | >= 15.0, < 15.4.1 |
| Apple | Tvos | < 18.4.1 |
| Apple | Visionos | < 2.4.1 |
| Apple | Ipados | < 18.4.1 |
| Apple | Iphone Os | < 18.4.1 |
Related Weaknesses (CWE)
References
- https://support.apple.com/en-us/122282Release NotesVendor Advisory
- https://support.apple.com/en-us/122400Release NotesVendor Advisory
- https://support.apple.com/en-us/122401Release NotesVendor Advisory
- https://support.apple.com/en-us/122402Release NotesVendor Advisory
- http://seclists.org/fulldisclosure/2025/Apr/26Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2025/Jun/14Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2025/Oct/0Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2025/Oct/3Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2025/Oct/4Mailing ListThird Party Advisory
- https://github.com/JGoyd/iOS-Attack-Chain-CVE-2025-31200-CVE-2025-31201/blob/maiExploitBroken Link
- https://github.com/cisagov/vulnrichment/issues/200Issue Tracking
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-US Government Resource
FAQ
What is CVE-2025-31201?
CVE-2025-31201 is a vulnerability with a CVSS score of 9.8 (CRITICAL). This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1. An attacker with arbitrary read and wr...
How severe is CVE-2025-31201?
CVE-2025-31201 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-31201?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Macos, Apple Tvos, Apple Visionos, Apple Ipados, Apple Iphone Os.