#VU107563 Improper authentication in Apple iOS and iPadOS - CVE-2025-31201

 

#VU107563 Improper authentication in Apple iOS and iPadOS - CVE-2025-31201

Published: April 16, 2025


Vulnerability identifier: #VU107563
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Amber
CVE-ID: CVE-2025-31201
CWE-ID: CWE-287
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild
Vulnerable software:
Apple iOS
iPadOS
Software vendor:
Apple Inc.

Description

The vulnerability allows a local application to bypass pointer authentication process.

The vulnerability exists due to an error in RPAC. A local application with read and write permissions can bypass pointer authentication and escalate privileges on the system.

Note, the vulnerability is being actively exploited in the wild.


Remediation

Install updates from vendor's website.

External links