CVE-2025-31200
Description
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1, watchOS 11.5. Processing an audio stream in a maliciously crafted media file may result in code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS released before iOS 18.4.1.
Summary dbcve.org
Memory corruption vulnerability in Apple media frameworks (audio stream processing) that allows code execution when processing maliciously crafted media files. The issue was addressed with improved bounds checking, indicating a buffer overflow or similar memory safety flaw in the audio processing code path.
Mitigation
Apply vendor-supplied security updates immediately: iOS 18.4.1, iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1, and watchOS 11.5. Given confirmed in-the-wild exploitation against targeted individuals, prioritize patching of exposed devices as urgent.