Apple Fixes Vulnerabilities Used in 'Extremely Sophisticated Attack' With Latest Updates
LIKE
TWEET
SHARE
PIN
SHARE
POST
MAIL
MORE
Posted April 16, 2025 at 6:34pm by iClarified
Apple released a series of software updates today, including iOS 18.4.1, iPadOS 18.4.1, and macOS 15.4.1, that patch two serious security vulnerabilities.
The company says that the issues were actively exploited in highly targeted and sophisticated attacks.
----- iOS 18.4.1 and iPadOS 18.4.1 Released April 16, 2025
CoreAudio Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 13.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later
Impact: Processing an audio stream in a maliciously crafted media file may result in code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.
Description: A memory corruption issue was addressed with improved bounds checking.
CVE-2025-31200: Apple and Google Threat Analysis Group
RPAC Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 13.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later
Impact: An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.
Description: This issue was addressed by removing the vulnerable code.
CVE-2025-31201: Apple -----
These same two CVEs apply to macOS Sequoia as well.