PT-2025-16878 · Apple · Visionos+6

CVE-2025-31201

·

Published

2024-04-16

·

Updated

2026-09-03

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions iOS versions prior to 18.4.1 iPadOS versions prior to 18.4.1 macOS Sequoia versions prior to 15.4.1 tvOS versions prior to 18.4.1 visionOS versions prior to 2.4.1
Description A memory out-of-bounds read in the RPAC component allows an attacker with arbitrary read and write capabilities to bypass Pointer Authentication, a security mechanism designed to prevent the modification of pointers in memory. The issue may be triggered via CoreAudio. There are reports that this flaw has been exploited in extremely sophisticated, targeted attacks against specific individuals using iOS.
Recommendations Update iOS to version 18.4.1. Update iPadOS to version 18.4.1. Update macOS Sequoia to version 15.4.1. Update tvOS to version 18.4.1. Update visionOS to version 2.4.1.

Exploit

Fix

DoS

RCE

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-04973
CVE-2025-31201

Affected Products

Coreaudio
Apple Macos
Ios
Ipados
Macos Sequoia
Tvos
Visionos