Improper authentication in Apple iOS and iPadOS - CVE-2025-31201

 

Improper authentication in Apple iOS and iPadOS - CVE-2025-31201

Published: April 16, 2025


Vulnerability identifier: #VU107563
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-31201
CWE-ID: CWE-287
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a local application to bypass pointer authentication process.

The vulnerability exists due to an error in RPAC. A local application with read and write permissions can bypass pointer authentication and escalate privileges on the system.

Note, the vulnerability is being actively exploited in the wild.


Affected software

Apple iOS
iPadOS
visionOS
macOS
tvOS

How to mitigate CVE-2025-31201

Install updates from vendor's website.

Apple iOS - update to 18.4.1 22E252
iPadOS - update to 18.4.1 22E252
iPadOS - update to
visionOS - update to 2.4.1
macOS - update to 15.4.1 24E263
tvOS - update to 18.4.1

External References

Related Security Bulletins