CVE-2025-31201 is a critical vulnerability affecting Apple's iOS, iPadOS, macOS, tvOS, and visionOS that allows an attacker with arbitrary read/write capabilities to bypass Pointer Authentication. This flaw carries a CVSS score of 9.8 (CRITICAL) due to its network-exploitable nature, low attack complexity, and high impact on confidentiality, integrity, and availability. Apple has confirmed that this zero-day vulnerability has been actively exploited in highly sophisticated, targeted attacks against specific individuals on iOS. While no public exploit code is available, the issue has garnered significant community discussion and media coverage, underscoring its severity and real-world impact. The vulnerability is addressed by removing the vulnerable code in tvOS 18.4.1, visionOS 2.4.1, iOS 18.4.1 and iPadOS 18.4.1, and macOS Sequoia 15.4.1.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 15.0, < 15.4.1CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
< 18.4.1CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | ||
< 2.4.1CPE matchmatch criteria | cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:* | ||
< 18.4.1CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 18.4.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.