CVE-2025-31200
CRITICAL KEVApple Macos < 15.4.1 - Out-of-Bounds Write
Title source: ruleDescription
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1, watchOS 11.5. Processing an audio stream in a maliciously crafted media file may result in code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS released before iOS 18.4.1.
Exploits (4)
nomisec
WRITEUP
183 stars
by JGoyd · poc
https://github.com/JGoyd/iOS-Attack-Chain-CVE-2025-31200-CVE-2025-31201
nomisec
WORKING POC
117 stars
by zhuowei · poc
https://github.com/zhuowei/apple-positional-audio-codec-invalid-header
nomisec
WRITEUP
1 stars
by serundengsapi · poc
https://github.com/serundengsapi/CVE-2025-31200-iOS-AudioConverter-RCE
References (15)
Scores
CVSS v3
9.8
EPSS
0.0205
EPSS Percentile
83.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2025-04-17
VulnCheck KEV
2025-04-16
ENISA EUVD
EUVD-2025-11380
CWE
CWE-119
Status
published
Products (11)
Apple/iOS and iPadOS
< 18.4.1
apple/ipados
< 18.4.1
apple/iphone_os
< 18.4.1
apple/macos
< 15.4.1
Apple/macOS
< 15.4.1
apple/tvos
< 18.4.1
Apple/tvOS
< 18.4.1
apple/visionos
< 2.4.1
Apple/visionOS
< 2.4.1
apple/watchos
< 11.5
... and 1 more
Published
Apr 16, 2025
KEV Added
Apr 17, 2025
Tracked Since
Feb 18, 2026