CVE-2025-31201
Description
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.
Summary dbcve.org
A Pointer Authentication (PAC) bypass vulnerability in Apple operating systems (iOS, iPadOS, macOS, tvOS, visionOS) that allows attackers with arbitrary read/write capability to circumvent PAC security checks. The vulnerable code was removed as the fix. This flaw has been actively exploited in extremely sophisticated targeted attacks against specific individuals.
Mitigation
Apply vendor-supplied security updates immediately: iOS 18.4.1/iPadOS 18.4.1 for iPhones/iPads, macOS Sequoia 15.4.1 for Macs, tvOS 18.4.1, and visionOS 2.4.1. Prioritize devices belonging to high-risk or targeted individuals.