Back to Labs
Security Advisory

CVE-2025-31201

About

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.

Weakness (CWE):CWE-1220

Rainforest analyst review

This Apple flaw lets an attacker who already has arbitrary memory read and write capability defeat Pointer Authentication (PAC), the hardware mitigation on Apple silicon that signs pointers to stop them from being corrupted into control-flow hijacks. PAC is a key barrier that turns a memory-corruption bug into a dead end; bypassing it lets an attacker forge valid pointer signatures and convert their read/write primitive into reliable code execution. Apple addressed it by removing the vulnerable code, and shipped fixes across iOS, iPadOS, macOS, tvOS, and visionOS.

Apple describes this as used in an extremely sophisticated attack against specific targeted individuals — the signature of mercenary spyware operations rather than commodity crime. It is a chain component: paired with a separate bug that provides the initial memory access, this bypass is what makes the exploit dependable, which is why these mitigation-defeats are so prized by high-end offensive tooling. The practical response is to install the fixed OS versions immediately across the whole Apple fleet, prioritizing individuals plausibly in scope for targeted surveillance — journalists, executives, dissidents — and to keep automatic updates enabled so future chain components are closed as they surface.

References

Related CVEs

No related CVEs.

Frequently asked questions

What is CVE-2025-31201?

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.

How severe is CVE-2025-31201?

CVE-2025-31201 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.

How is CVE-2025-31201 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2025-31201?

Public advisories list the following as affected: ipados, iphone os, macos, tvos, visionos. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2025-31201?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email