Apple plugs zero-day holes used in targeted iPhone attacks (CVE-2025-31200, CVE-2025-31201)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-24200 | Incorrect Authorization in Apple iOS/iPadOS Lets Attackers Disable USB Restricted Mode CVE-2025-24200 is an incorrect authorization flaw (CWE-863) in Apple iOS and iPadOS, caused by an authorization issue in state management that Apple resolved with improved state handling. An attacker with brief physical access to a locked device can exploit the flaw to disable USB Restricted Mode, the feature that locks down a locked iPhone or iPad's USB data port against accessories after a set period. This allows USB accessories, including data-extraction and attack peripherals, to communicate with the device while it remains locked, with a high confidentiality and integrity impact (CVSS 6.1, physical attack vector). Any iPhone or iPad user running a version prior to the applicable fixed release is affected, with fixes shipped in iOS 15.8.4, iOS 16.7.11, iOS 18.3.1, iPadOS 15.8.4, iPadOS 16.7.11, iPadOS 17.7.5, and iPadOS 18.3.1. Apple reports the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-12. Do: Update iPhones to iOS 15.8.4, iOS 16.7.11, or iOS 18.3.1 and iPads to iPadOS 15.8.4, 16.7.11, 17.7.5, or 18.3.1 as applicable to each device's branch, checking Settings > General > Software Update for unmanaged devices. Because exploitation requires physical access, prioritize high-risk users (executives, journalists, government personnel), confirm no fleet devices remain on unpatched builds, and avoid untrusted USB accessories and charging ports until updated. CISA's KEV listing requires federal agencies to apply the vendor patch per the required action or discontinue use of the product. | 6.1 | 4% | KEV |
| mass≈1 billion+ devices (Apple's active installed base; every iPhone/iPad running a pre-patch iOS/iPadOS release at the time of disclosure) | |
| CVE-2025-31200 +1 in the same advisory: …31201 | Memory Corruption in Apple iOS, iPadOS, macOS Audio Processing Enables Code Execution CVE-2025-31200 is a memory corruption flaw (CWE-119) in Apple's audio stream handling, fixed with improved bounds checking, that allows code execution when a device processes an audio stream in a maliciously crafted media file. An attacker who can deliver such a file to a vulnerable Apple device can gain arbitrary code execution with full confidentiality, integrity, and availability impact (CVSS 3.1: 9.8 critical, network vector). Affected products are iOS, iPadOS, macOS (Sequoia), tvOS, visionOS, and watchOS on versions released before the April 2025 fixes. Apple stated the issue was exploited in an extremely sophisticated attack against specific targeted individuals on iOS versions before 18.4.1, and CISA added it to the KEV on 2025-04-17; EPSS estimates a 19.7% (97th percentile) probability of exploitation within 30 days. Public analyses describe it chained with the WebKit flaw CVE-2025-31201, which Apple patched in the same emergency updates. Do: Update all Apple devices immediately: iOS/iPadOS 18.4.1 or later, macOS Sequoia 15.4.1 or later, tvOS 18.4.1 or later, visionOS 2.4.1 or later, and watchOS 11.5 or later; the same updates also fix the related actively exploited WebKit zero-day CVE-2025-31201. The flaw is in CISA KEV (added 2025-04-17), so US federal agencies must apply the updates per BOD 22-01 or discontinue use. Verify installed OS versions in Settings > General > About (iOS/iPadOS) or About This Mac, and prioritize high-risk/targeted users for immediate patching and review. | 9.8 | 19% | KEV PoC ×2 |
| masswell over 1 billion Apple devices (iOS/iPadOS/macOS active installed base; all devices on pre-18.4.1/15.4.1 OS versions at disclosure were affected) |
Full article338 words · extracted from helpnetsecurity.com · click to collapse
Apple has released emergency security updates for iOS/iPadOS, macOS, tvOS and visionOS that fix two zero-day vulnerabilities (CVE-2025-31200, CVE-2025-31201) that have been exploited “in an extremely sophisticated attack against specific targeted individuals on iOS.”

CVE-2025-31200 and CVE-2025-31201
CVE-2025-31200 affects CoreAudio, an API Apple devices use for processing audio. The memory corruption vulnerability can be triggered with a maliciously crafted media file: when the audio stream in it is processed, it allows attackers to execute malicious code.
CVE-2025-31201 is an issue in RPAC (Return Pointer Authentication Code), a security feature that aims to thwart return-oriented programming attacks and similar code reuse exploits.
The vulnerability allows an attacker with arbitrary read and write capability to bypass Pointer Authentication. Apple fixed the security hole by removing the vulnerable code.
Update ASAP
CVE-2025-31200 was discovered by Apple and the Google Threat Analysis Group (TAG), which uncovers and investigates state-sponsored attacks and other advanced persistent threats. CVE-2025-31201 was flagged by Apple.
As is typical for Apple, the company did not share details about the attacks during which these vulnerabilities have been exploited – we have to be satisfied with their categorization of the attacks as “extremely sophisticated”.
(Apple has used the same wording earlier this year, when providing a fix for CVE-2025-24200, a vulnerability that allowed attackers with physical access to targeted locked devices to disable USB Restricted Mode.)
These latest attacks were aimed against specific individuals, which means that Apple users that are not journalists, activists/dissidents, politicians/diplomats, researchers and executives in sensitive fields, or other users that have access to valuable data or communications, are unlikely to be in grave danger.
Nevertheless, all users should implement the provided security updates as soon as possible.
High-risk users should consider enabling Lockdown Mode on their iOS and macOS devices and consult with digital security experts (e.g., Access Now’s Digital Security Helpline) on how to improve their digital security practices.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/04/17/apple-plugs-zero-days-holes-used-in-targeted-iphone-attacks-cve-2025-31200-cve-2025-31201/