Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Todsacerdoti

#26201of 56,330
9.8Total CVSS
Vulnerabilities · 1
PT-2025-16877
9.8
2024-04-16
Apple · Macos Sequoia · CVE-2025-31200
**Name of the Vulnerable Software and Affected Versions** macOS Sequoia versions prior to 15.4.1 tvOS versions prior to 18.4.1 visionOS versions prior to 2.4.1 iOS versions prior to 18.4.1 iPadOS versions prior to 18.4.1 watchOS versions prior to 11.5 **Description** A memory corruption issue exists in the RPAC and CoreAudio components due to out-of-bounds memory reads. Processing an audio stream within a maliciously crafted media file can allow a remote attacker to bypass security restrictions or execute arbitrary code. This issue involves the `InferProfileFromCodecConfigs()` function, where improper bounds checking occurs when indexing into global arrays using calculated step sizes related to Higher Order Ambisonics (a method of representing sound as a spatial sound-field). There are reports that this issue has been exploited in extremely sophisticated attacks targeting specific individuals on iOS. **Recommendations** Update macOS Sequoia to version 15.4.1. Update tvOS to version 18.4.1. Update visionOS to version 2.4.1. Update iOS to version 18.4.1. Update iPadOS to version 18.4.1. Update watchOS to version 11.5.