logo

Apple Zero-Days Under 'Sophisticated Attack,' but Details Lacking

ID: 87ac775c-8ff6-5920-b96a-bd06cac73f02

STIX ID: report--87ac775c-8ff6-5920-b96a-bd06cac73f02

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-04-18

Date Updated: 2026-05-05

Author: Rob Wright

...
...

Apple disclosed two zero-day vulnerabilities affecting iOS, iPadOS, macOS, tvOS, and visionOS — a CoreAudio memory-corruption bug (CVE-2025-31200) enabling remote code execution and an RPAC hardware flaw (CVE-2025-31201) that can bypass pointer authentication — both reported as exploited in the wild. The advisory provided minimal technical or attribution details; discovery was credited to Apple and Google TAG, and security researchers warn the lack of transparency hampers detection and mitigation of what may be targeted, sophisticated (potentially nation-state) attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.