CVE-2025-31200
KEV PoC ×2mass1Memory Corruption in Apple iOS, iPadOS, macOS Audio Processing Enables Code Execution
CISA: Apple Multiple Products Memory Corruption Vulnerability
CVE-2025-31200 is a memory corruption flaw (CWE-119) in Apple's audio stream handling, fixed with improved bounds checking, that allows code execution when a device processes an audio stream in a maliciously crafted media file. An attacker who can deliver such a file to a vulnerable Apple device can gain arbitrary code execution with full confidentiality, integrity, and availability impact (CVSS 3.1: 9.8 critical, network vector). Affected products are iOS, iPadOS, macOS (Sequoia), tvOS, visionOS, and watchOS on versions released before the April 2025 fixes. Apple stated the issue was exploited in an extremely sophisticated attack against specific targeted individuals on iOS versions before 18.4.1, and CISA added it to the KEV on 2025-04-17; EPSS estimates a 19.7% (97th percentile) probability of exploitation within 30 days. Public analyses describe it chained with the WebKit flaw CVE-2025-31201, which Apple patched in the same emergency updates.
What to do: Update all Apple devices immediately: iOS/iPadOS 18.4.1 or later, macOS Sequoia 15.4.1 or later, tvOS 18.4.1 or later, visionOS 2.4.1 or later, and watchOS 11.5 or later; the same updates also fix the related actively exploited WebKit zero-day CVE-2025-31201. The flaw is in CISA KEV (added 2025-04-17), so US federal agencies must apply the updates per BOD 22-01 or discontinue use. Verify installed OS versions in Settings > General > About (iOS/iPadOS) or About This Mac, and prioritize high-risk/targeted users for immediate patching and review.
| Apple iOS (iPhone OS) | versions prior to iOS 18.4.1 (fixed in iOS 18.4.1) |
| Apple iPadOS | versions prior to iPadOS 18.4.1 (fixed in iPadOS 18.4.1) |
| Apple macOS | macOS Sequoia versions prior to 15.4.1 (fixed in macOS Sequoia 15.4.1) |
| Apple tvOS | versions prior to tvOS 18.4.1 (fixed in tvOS 18.4.1) |
| Apple visionOS | versions prior to visionOS 2.4.1 (fixed in visionOS 2.4.1) |
| Apple watchOS | versions prior to watchOS 11.5 (fixed in watchOS 11.5) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1, watchOS 11.5. Processing an audio stream in a maliciously crafted media file may result in code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS released before iOS 18.4.1.
- Affected
- Apple Multiple Products
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- macos, tvos, visionos, ipados, iphone os, watchos
- Weakness
- CWE-119
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H