PT-2025-16878 · Apple · Tvos +6
Published
2024-04-16
·
Updated
2025-09-12
·
CVE-2025-31201
7.5
High
Base vector | Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
tvOS versions prior to 18.4.1
visionOS versions prior to 2.4.1
iOS versions prior to 18.4.1
iPadOS versions prior to 18.4.1
macOS Sequoia versions prior to 15.4.1
Description:
This issue was addressed by removing the vulnerable code. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS. The vulnerability is related to the Reconfigurable Processing Architecture Core (RPAC), a hardware component in newer Apple Silicon chips, and allows attackers to bypass Apple's Pointer Authentication Code (PAC).
Recommendations:
For tvOS versions prior to 18.4.1, update to tvOS 18.4.1 to fix the issue.
For visionOS versions prior to 2.4.1, update to visionOS 2.4.1 to fix the issue.
For iOS versions prior to 18.4.1, update to iOS 18.4.1 to fix the issue.
For iPadOS versions prior to 18.4.1, update to iPadOS 18.4.1 to fix the issue.
For macOS Sequoia versions prior to 15.4.1, update to macOS Sequoia 15.4.1 to fix the issue.
Fix
Memory Corruption
Weakness Enumeration
Related Identifiers
Affected Products
References · 116
- https://bdu.fstec.ru/vul/2025-04973 · Security Note
- https://nvd.nist.gov/vuln/detail/CVE-2025-31201 · Security Note
- https://support.apple.com/en-us/122402 · Security Note, Vendor Advisory
- https://support.apple.com/en-us/122400 · Security Note, Vendor Advisory
- https://support.apple.com/en-us/122401 · Security Note, Vendor Advisory
- https://support.apple.com/en-us/122282 · Security Note, Vendor Advisory
- https://twitter.com/matrosov/status/1914128313842647322 · Twitter Post
- https://reddit.com/r/CVEWatch/comments/1k29ss2/top_10_trending_cves_18042025 · Reddit Post
- https://t.me/cvetracker/21792 · Telegram Post
- https://twitter.com/minacris_/status/1918924800606556162 · Twitter Post
- https://reddit.com/r/CVEWatch/comments/1k4gvcl/top_10_trending_cves_21042025 · Reddit Post
- https://twitter.com/xvonfers/status/1912561166464827854 · Twitter Post
- https://twitter.com/transilienceai/status/1913561457918099576 · Twitter Post
- https://twitter.com/AskPerplexity/status/1912656999487004738 · Twitter Post
- https://twitter.com/socradar/status/1912796928087326725 · Twitter Post