Junglewise Threat Intelligence

CVE-2025-31201: Apple Multiple Products Arbitrary Read and Write Vulnerability

CVE-2025-31201 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-04-17

Technologies: Apple iPadOS, Apple Visionos, Apple macOS Sequoia, Apple Tvos, Apple Multiple Products. Vendors: Apple.

Executive brief

Apple iOS, iPadOS, macOS, tvOS, and visionOS contain a vulnerability that allows an attacker with arbitrary read and write capabilities to bypass Pointer Authentication. The issue was addressed by removing the vulnerable code in various OS updates. Apple has received reports that this vulnerability may have been exploited in targeted attacks against iOS users.

Affected products

  • Apple iOS before 18.4.1
  • Apple iPadOS before 18.4.1
  • Apple macOS Sequoia before 15.4.1
  • Apple tvOS before 18.4.1
  • Apple visionOS before 2.4.1

Timeline

  • 2025-04-17: disclosed
  • 2025-04-17: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-04-17: patched: Fixed in iOS 18.4.1, iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, and visionOS 2.4.1
  • exploited: Apple is aware of reports of exploitation in sophisticated attacks against targeted individuals.

Related threats