CVE-2025-31201
KEV PoC massPointer Authentication Bypass in Apple iOS, iPadOS, macOS Sequoia, tvOS, and visionOS
CISA: Apple Multiple Products Arbitrary Read and Write Vulnerability
CVE-2025-31201 is a vulnerability in Apple's iOS, iPadOS, macOS Sequoia, tvOS, and visionOS that allows an attacker who has already gained arbitrary read and write capability on a device to bypass Pointer Authentication (CWE-1220), Apple's hardware-backed mitigation that normally prevents forged code execution on Apple silicon. It is not an entry-point flaw on its own; public references and news coverage show it being used as the second stage of an attack chain alongside the WebKit flaw CVE-2025-31200, which is what makes the network-reachable CVSS 3.1 score of 9.8 (critical) meaningful. By defeating Pointer Authentication, the attacker converts memory read/write primitives into the ability to run forged or unsigned code with elevated effectiveness, enabling full device compromise when chained. Any user of an iPhone, iPad, Mac (Sequoia), Apple TV, or Vision Pro running a version earlier than the fixed releases is potentially affected. Apple patched the issue by removing the vulnerable code in iOS 18.4.1/iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, and visionOS 2.4.1, and reports it was exploited in an 'extremely sophisticated' targeted attack against specific individuals on iOS; the CVE was added to CISA KEV on 2025-04-17.
What to do: Upgrade iPhones and iPads to iOS/iPadOS 18.4.1 or later, Macs on macOS Sequoia to 15.4.1 or later, Apple TVs to tvOS 18.4.1 or later, and Vision Pro units to visionOS 2.4.1 or later; the fix removed the vulnerable code, so there is no configuration workaround. Because this flaw is exploited as part of a chain with the WebKit zero-day CVE-2025-31200, patching both (they ship in the same releases) is essential, and organizations should hunt for indicators of compromise on high-value/targeted users. Federal agencies must apply the vendor fixes per CISA BOD 22-01 guidance (KEV deadline applies; added 2025-04-17) or discontinue use of affected products.
| Apple iPhone OS (iOS) | versions prior to iOS 18.4.1 (fixed in 18.4.1) |
| Apple iPadOS | versions prior to iPadOS 18.4.1 (fixed in 18.4.1) |
| Apple macOS (Sequoia) | macOS Sequoia versions prior to 15.4.1 (fixed in 15.4.1) |
| Apple tvOS | versions prior to tvOS 18.4.1 (fixed in 18.4.1) |
| Apple visionOS | versions prior to visionOS 2.4.1 (fixed in 2.4.1) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.
- Affected
- Apple Multiple Products
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- macos, tvos, visionos, ipados, iphone os
- Weakness
- CWE-1220
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H