PT-2025-16877 · Apple · Visionos +5
Todsacerdoti
·
Published
2024-04-16
·
Updated
2025-07-27
·
CVE-2025-31200
7.6
High
Base vector | Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
**Name of the Vulnerable Software and Affected Versions:**
Apple macOS Sequoia
Apple tvOS versions 18.4.1 and earlier
Apple visionOS versions 2.4.1 and earlier
Apple iOS versions 18.4.1 and earlier
Apple iPadOS versions 18.4.1 and earlier
Apple watchOS versions prior to 11.5
**Description:**
A memory corruption issue exists in the CoreAudio framework, addressed through improved bounds checking. Processing a maliciously crafted audio stream within a media file may lead to code execution. Apple is aware of reports indicating exploitation of this issue in highly sophisticated attacks targeting specific individuals on iOS.
**Recommendations:**
Apple macOS Sequoia versions prior to 15.4.1
Apple tvOS versions prior to 18.4.1
Apple visionOS versions prior to 2.4.1
Apple iOS versions prior to 18.4.1
Apple iPadOS versions prior to 18.4.1
Apple watchOS versions prior to 11.5
Exploit
Fix
RCE
Memory Corruption
Weakness Enumeration
Related Identifiers
Affected Products
References · 157
- 🔥 https://github.com/JGoyd/CVE-2025-31200-iOS-AudioConverter-RCE · Exploit
- 🔥 https://blog.noahhw.dev/posts/cve-2025-31200 · Exploit
- https://nvd.nist.gov/vuln/detail/CVE-2025-31200 · Security Note
- https://support.apple.com/en-us/122402 · Security Note, Vendor Advisory
- https://support.apple.com/en-us/122401 · Security Note, Vendor Advisory
- https://support.apple.com/en-us/122282 · Security Note, Vendor Advisory
- https://bdu.fstec.ru/vul/2025-04742 · Security Note
- https://support.apple.com/en-us/122400 · Security Note, Vendor Advisory
- https://t.me/cvetracker/21791 · Telegram Post
- https://twitter.com/Alchemyst0x/status/1912789411139404181 · Twitter Post
- https://twitter.com/AIDE_ink/status/1912734729830600930 · Twitter Post
- https://reddit.com/r/CVEWatch/comments/1k6oj14/top_10_trending_cves_24042025 · Reddit Post
- https://twitter.com/samilaiho/status/1928328324239028662 · Twitter Post
- https://twitter.com/jawconsultinguk/status/1912807392892576190 · Twitter Post
- https://t.me/secharvester/19079 · Telegram Post