Apple Patches Two Zero-Days Used in ‘Extremely Sophisticated’ Attacks
ID: ba6bbc07-3fa8-583e-8ad0-6c3f9c314ce2
STIX ID: report--ba6bbc07-3fa8-583e-8ad0-6c3f9c314ce2
Feed Name: TechRepublic Security
Apple issued emergency updates (iOS 18.4.1 and macOS Sequoia 15.4.1) to patch two actively exploited zero-day vulnerabilities: CVE-2025-31200 in CoreAudio, which can enable device takeover via a malicious media file, and CVE-2025-31201 in RPAC, which allows bypassing Pointer Authentication; the flaws were used in highly targeted, sophisticated attacks against specific individuals and affect iPhone XS and newer, iPad 7th generation and newer, Macs running Sequoia, Apple TV HD/4K, and Apple Vision Pro.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
