logo

Apple Patches Two Zero-Days Used in ‘Extremely Sophisticated’ Attacks

ID: ba6bbc07-3fa8-583e-8ad0-6c3f9c314ce2

STIX ID: report--ba6bbc07-3fa8-583e-8ad0-6c3f9c314ce2

Feed Name: TechRepublic Security

Threat Score
85/100

Date Published: 2025-04-17

Date Updated: 2026-04-23

Author: Aminu Abdullahi

...
...

Apple issued emergency updates (iOS 18.4.1 and macOS Sequoia 15.4.1) to patch two actively exploited zero-day vulnerabilities: CVE-2025-31200 in CoreAudio, which can enable device takeover via a malicious media file, and CVE-2025-31201 in RPAC, which allows bypassing Pointer Authentication; the flaws were used in highly targeted, sophisticated attacks against specific individuals and affect iPhone XS and newer, iPad 7th generation and newer, Macs running Sequoia, Apple TV HD/4K, and Apple Vision Pro.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.