V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2025-31201
CVE
Critical KEVConfirmedExploit available

This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 18.4.1, visionOS 2.4.1, iOS iOS 18.4.1 and iPadOS 18.…

CVSS
9.8
Critical
EPSS
0.03
p87
Published
2025-01-01
Updated
2025-04-17
Description

This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 18.4.1, visionOS 2.4.1, iOS iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.

Tags · CWE
KEVPre-auth
CWE-1220
CAPEC-1
CAPEC-180
Affected products
Ipados < 18.4.1
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2025-01-01
Published
2025-04-17
Added to KEV
2025-04-17
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.034 · p87
Known exploited (KEV)
Yes
MITRE ATT&CK
Inferred via CAPEC
Known exploits — Сканер-ВС
CVE-2025-31201
cisa · https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Enterprise
Affected software
ProductVendorStatus
ipados*Exploited
iphone_os*Exploited
macos*Exploited
tvos*Exploited
visionos*Exploited
Source databases
CVE
Related vulnerabilities