CVE-2025-31200

A memory corruption issue was addressed with improved bounds checking. This issue is fixed in tvOS 18.4.1, visionOS 2.4.1, iOS iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1. Processing an audio stream in a maliciously crafted media file may result in code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.
Configurations

Configuration 1 (hide)

cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*

Configuration 4 (hide)

cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*

Configuration 5 (hide)

cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

Configuration 6 (hide)

cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

History

25 Nov 2025, 13:42

Type Values Removed Values Added
References () https://github.com/JGoyd/iOS-Attack-Chain-CVE-2025-31200-CVE-2025-31201/blob/main/Remote%20Crypto%20Attack%20Chain%20.md - () https://github.com/JGoyd/iOS-Attack-Chain-CVE-2025-31200-CVE-2025-31201/blob/main/Remote%20Crypto%20Attack%20Chain%20.md - Exploit
References () https://github.com/cisagov/vulnrichment/issues/200 - () https://github.com/cisagov/vulnrichment/issues/200 - Issue Tracking

24 Nov 2025, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.1
v2 : unknown
v3 : 9.8
References
  • () https://github.com/JGoyd/iOS-Attack-Chain-CVE-2025-31200-CVE-2025-31201/blob/main/Remote%20Crypto%20Attack%20Chain%20.md -
  • () https://github.com/cisagov/vulnrichment/issues/200 -
CWE CWE-119

04 Nov 2025, 16:21

Type Values Removed Values Added
First Time Apple watchos
CPE cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
References
  • () http://seclists.org/fulldisclosure/2025/Apr/26 - Mailing List, Third Party Advisory
  • () http://seclists.org/fulldisclosure/2025/Jun/14 - Mailing List, Third Party Advisory
  • () http://seclists.org/fulldisclosure/2025/May/10 - Mailing List, Third Party Advisory
  • () http://seclists.org/fulldisclosure/2025/Oct/0 - Mailing List, Third Party Advisory
  • () http://seclists.org/fulldisclosure/2025/Oct/4 - Mailing List, Third Party Advisory

Information

Published : 2025-04-16 19:15

Updated : 2025-11-25 13:42


NVD link : CVE-2025-31200

Mitre link : CVE-2025-31200

CVE.ORG link : CVE-2025-31200


JSON object : View

Products Affected

apple

  • watchos
  • visionos
  • ipados
  • iphone_os
  • tvos
  • macos
CWE
CWE-787

Out-of-bounds Write

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer