Junglewise Threat Intelligence

CVE-2025-31200: Apple Multiple Products Memory Corruption Vulnerability

CVE-2025-31200 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-04-17

Technologies: Apple watchOS, Apple iPadOS, Apple Visionos, Apple macOS Sequoia, Apple Tvos, Apple Multiple Products. Vendors: Apple.

Executive brief

A memory corruption vulnerability in multiple Apple operating systems allows for remote code execution when processing a maliciously crafted audio stream. The issue was addressed through improved bounds checking in various OS updates.

Affected products

  • Apple iOS before 18.4.1
  • Apple iPadOS before 18.4.1
  • Apple macOS Sequoia before 15.4.1
  • Apple tvOS before 18.4.1
  • Apple visionOS before 2.4.1
  • Apple watchOS before 11.5

Timeline

  • 2025-04-17: disclosed
  • 2025-04-17: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-04-17: patched: Fixed in iOS 18.4.1, iPadOS 18.4.1, macOS 15.4.1, tvOS 18.4.1, visionOS 2.4.1, and watchOS 11.5
  • exploited: Apple reported awareness of exploitation in sophisticated attacks against targeted individuals on iOS versions prior to 18.4.1.

Related threats