CRITICAL

CVE-2025-31201

Apple macOS 2025-04-16 CVSS v3.1
CVSS
9.8
KEV

Description

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.

Summary dbcve.org

A Pointer Authentication (PAC) bypass vulnerability in Apple operating systems (iOS, iPadOS, macOS, tvOS, visionOS) that allows attackers with arbitrary read/write capability to circumvent PAC security checks. The vulnerable code was removed as the fix. This flaw has been actively exploited in extremely sophisticated targeted attacks against specific individuals.

Mitigation

Apply vendor-supplied security updates immediately: iOS 18.4.1/iPadOS 18.4.1 for iPhones/iPads, macOS Sequoia 15.4.1 for Macs, tvOS 18.4.1, and visionOS 2.4.1. Prioritize devices belonging to high-risk or targeted individuals.

Proof of Concept

Weakness (CWE)

CWE-1220

EPSS Score

13.85%
Probability of exploitation in next 30 days
96.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE