Improper authentication in Apple iOS and iPadOS - CVE-2025-31201
Published: April 16, 2025
Vulnerability identifier: #VU107563
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-31201
CWE-ID: CWE-287
Exploitation vector: Local access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a local application to bypass pointer authentication process.
The vulnerability exists due to an error in RPAC. A local application with read and write permissions can bypass pointer authentication and escalate privileges on the system.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Apple iOS
iPadOS
visionOS
macOS
tvOS
iPadOS
visionOS
macOS
tvOS
How to mitigate CVE-2025-31201
Install updates from vendor's website.
Apple iOS - update to 18.4.1 22E252
iPadOS - update to 18.4.1 22E252
iPadOS - update to
visionOS - update to 2.4.1
macOS - update to 15.4.1 24E263
tvOS - update to 18.4.1
iPadOS - update to 18.4.1 22E252
iPadOS - update to
visionOS - update to 2.4.1
macOS - update to 15.4.1 24E263
tvOS - update to 18.4.1