#VU107563 Improper authentication in Apple iOS and iPadOS - CVE-2025-31201
Published: April 16, 2025
Vulnerability identifier: #VU107563
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Amber
CVE-ID: CVE-2025-31201
CWE-ID: CWE-287
Exploitation vector: Local access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerable software:
Apple iOS
iPadOS
Apple iOS
iPadOS
Software vendor:
Apple Inc.
Apple Inc.
Description
The vulnerability allows a local application to bypass pointer authentication process.
The vulnerability exists due to an error in RPAC. A local application with read and write permissions can bypass pointer authentication and escalate privileges on the system.
Note, the vulnerability is being actively exploited in the wild.
Remediation
Install updates from vendor's website.