Improper authentication in Apple iOS and iPadOS - CVE-2025-31201

 

Improper authentication in Apple iOS and iPadOS - CVE-2025-31201

Published: April 16, 2025


Vulnerability identifier: #VU107563
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Amber
CVE-ID: CVE-2025-31201
CWE-ID: CWE-287
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild
Vendor: Apple Inc.
Affected software:
Apple iOS
iPadOS

Detailed vulnerability description

The vulnerability allows a local application to bypass pointer authentication process.

The vulnerability exists due to an error in RPAC. A local application with read and write permissions can bypass pointer authentication and escalate privileges on the system.

Note, the vulnerability is being actively exploited in the wild.


How to mitigate CVE-2025-31201

Install updates from vendor's website.

Sources