ZeroHour

CVE-2025-31201

KEV PoC mass

Pointer Authentication Bypass in Apple iOS, iPadOS, macOS Sequoia, tvOS, and visionOS

CISA: Apple Multiple Products Arbitrary Read and Write Vulnerability

CVSS 3.1
9.8 critical
EPSS
14%p96
Published
()
KEV added
AI analysis

CVE-2025-31201 is a vulnerability in Apple's iOS, iPadOS, macOS Sequoia, tvOS, and visionOS that allows an attacker who has already gained arbitrary read and write capability on a device to bypass Pointer Authentication (CWE-1220), Apple's hardware-backed mitigation that normally prevents forged code execution on Apple silicon. It is not an entry-point flaw on its own; public references and news coverage show it being used as the second stage of an attack chain alongside the WebKit flaw CVE-2025-31200, which is what makes the network-reachable CVSS 3.1 score of 9.8 (critical) meaningful. By defeating Pointer Authentication, the attacker converts memory read/write primitives into the ability to run forged or unsigned code with elevated effectiveness, enabling full device compromise when chained. Any user of an iPhone, iPad, Mac (Sequoia), Apple TV, or Vision Pro running a version earlier than the fixed releases is potentially affected. Apple patched the issue by removing the vulnerable code in iOS 18.4.1/iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, and visionOS 2.4.1, and reports it was exploited in an 'extremely sophisticated' targeted attack against specific individuals on iOS; the CVE was added to CISA KEV on 2025-04-17.

What to do: Upgrade iPhones and iPads to iOS/iPadOS 18.4.1 or later, Macs on macOS Sequoia to 15.4.1 or later, Apple TVs to tvOS 18.4.1 or later, and Vision Pro units to visionOS 2.4.1 or later; the fix removed the vulnerable code, so there is no configuration workaround. Because this flaw is exploited as part of a chain with the WebKit zero-day CVE-2025-31200, patching both (they ship in the same releases) is essential, and organizations should hunt for indicators of compromise on high-value/targeted users. Federal agencies must apply the vendor fixes per CISA BOD 22-01 guidance (KEV deadline applies; added 2025-04-17) or discontinue use of affected products.

Affected
Apple iPhone OS (iOS)versions prior to iOS 18.4.1 (fixed in 18.4.1)
Apple iPadOSversions prior to iPadOS 18.4.1 (fixed in 18.4.1)
Apple macOS (Sequoia)macOS Sequoia versions prior to 15.4.1 (fixed in 15.4.1)
Apple tvOSversions prior to tvOS 18.4.1 (fixed in 18.4.1)
Apple visionOSversions prior to visionOS 2.4.1 (fixed in 2.4.1)
Estimated exposure
masshundreds of millions of devices (share of Apple's billion-plus active iPhone/iPad/Mac/Apple TV/Vision Pro install base running pre-patch versions at disclosure) — Estimate based on Apple's active installed base, which is in the billions of devices, multiplied by the typical fraction of the fleet running a version older than the just-released patch at disclosure time; actual exploitation per Apple…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
apple
Products
macos, tvos, visionos, ipados, iphone os
Weakness
CWE-1220
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news