HomeVulnerabilityApple Patches Two Actively Exploited iOS Flaws Utilized in Subtle Focused Attacks

Apple Patches Two Actively Exploited iOS Flaws Utilized in Subtle Focused Attacks

Apple on Wednesday launched security updates for iOS, iPadOS, macOS Sequoia, tvOS, and visionOS to deal with two security flaws that it stated have come underneath energetic exploitation within the wild.

The vulnerabilities in query are listed beneath –

  • CVE-2025-31200 (CVSS rating: 7.5) – A reminiscence corruption vulnerability within the Core Audio framework that would permit code execution when processing an audio stream in a maliciously crafted media file
  • CVE-2025-31201 (CVSS rating: 6.8) – A vulnerability within the RPAC element that could possibly be utilized by an attacker with arbitrary learn and write functionality to bypass Pointer Authentication
Cybersecurity

The iPhone maker stated it addressed CVE-2025-31200 with improved bounds checking and CVE-2025-31201 by eradicating the susceptible part of code.

Each the vulnerabilities have been credited to Apple, together with Google Risk Evaluation Group (TAG) for reporting CVE-2025-31200.

Apple, as is usually the case with such advisories, stated it is conscious that the problems have been “exploited in an especially refined assault towards particular focused people on iOS.”

See also  A Resolution to SOAR's Unfulfilled Guarantees

With the most recent growth, Apple has addressed a complete of 5 actively exploited zero-days in its software program because the begin of the 12 months –

  • CVE-2025-24085 (CVSS rating: 7.8) – A use-after-free bug within the Core Media element that would allow a malicious software already put in on a tool to raise privileges
  • CVE-2025-24200 (CVSS rating: 4.6) – An authorization challenge within the Accessibility element that would allow an attacker to disable USB Restricted Mode on a locked gadget as a part of a cyber-physical assault
  • CVE-2025-24201 (CVSS rating: 7.1) – An out-of-bounds write challenge within the WebKit element that could possibly be exploited to interrupt out of the Net Content material sandbox utilizing maliciously crafted net content material
Cybersecurity

The updates can be found for the next gadgets and working methods –

  • iOS 18.4.1 and iPadOS 18.4.1 – iPhone XS and later, iPad Professional 13-inch, iPad Professional 13.9-inch third technology and later, iPad Professional 11-inch 1st technology and later, iPad Air third technology and later, iPad seventh technology and later, and iPad mini fifth technology and later
  • macOS Sequoia 15.4.1 – Macs operating macOS Sequoia
  • tvOS 18.4.1 – Apple TV HD and Apple TV 4K (all fashions)
  • visionOS 2.4.1 – Apple Imaginative and prescient Professional
See also  New Rising APT Menace Exploiting WinRAR Flaw

In gentle of energetic exploitation, customers are suggested to replace their gadgets to the most recent model to safeguard towards dangers.

- Advertisment -spot_img
RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -

Most Popular