CVE-2025-31200Active Exploitation(apple / ipados)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1, watchOS 11.5. Processing an audio stream in a maliciously crafted media file may result in code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS released before iOS 18.4.1.

4.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-05-08. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-119

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • tvos

Threat summary

  • Active exploitation appears in 4 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 4 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Peaked at 3 mentions on most recent observed day (2026-09-03)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
ipadosiphone_osmacostvosvisionoswatchos

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-01: 1Mentions · 2026-09-03: 3Active Exploitation · 2026-02-01: 1Active Exploitation · 2026-09-03: 3Patch / Workaround · 2026-09-03: 2Technical Details · 2026-02-01: 1Technical Details · 2026-09-03: 102-0109-03
Signal classification1 categories
Active Exploitation
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-011
Active Exploitation1
2026-09-033
Active Exploitation3
Full discourse4 posts
  • Bill Marczak@billmarczak
    Active Exploitation

    Seems like CVE-2025-31200 and CVE-2025-31201 were NSO Group! Most recent zero-click chain that appears to be attributable to them https://support.apple.com/en-us/122282 (Ref: https://citizenlab.ca/research/pegasus-spyware-infection-of-serbian-activist/)

    Post summary

    The post indicates that CVE-2025-31200 and CVE-2025-31201 are tied to an NSO Group zero‑click chain, implying active exploitation in the wild, but provides no PoC, exploit code, or technical details.

    13722019918.2K
    12.9K followersView on X
  • ︎@0xocdsec
    Active Exploitation

    "... CVE-2025-31201 (PAC bypass vulnerability) Combined with CVE-2025-31200, it forms a zero-interaction attack chain of "user-mode RCE → kernel privilege escalation → persistence", requiring no further interaction. triggered simply by clicking and receiving an iMessage ...."

    Post summary

    The post claims that CVE-2025-31201, combined with CVE-2025-31200, forms a zero-interaction attack chain that can be triggered simply by clicking an iMessage, indicating active exploitation in the wild.

    11020467
    4.3K followersView on X
  • Smart Global Technologies@inviolableio
    Active Exploitation

    CVE-2025-31200 & CVE-2025-31201 — the zero-click chain Apple patched this year — now appears attributable to NSO Group (Citizen Lab). Patching closes the door. It can't tell you if the attack landed before you updated. Forensic analysis can. https://inviolable.online

    Post summary

    The post reports that Apple’s patched zero‑click chain (CVE‑2025‑31200/31 2001) was exploited by NSO Group, but no PoC or exploit code is shared, only a call to patch.

    0000055
    72 followersView on X
  • Smart Global Technologies@inviolableio
    Active Exploitation

    Zero-click: no tap, no link, no mistake needed. CVE-2025-31200/31201 were patched in April — targets were already hit before the fix existed. Attribution always comes after. Forensics is what closes that gap. https://x.com/billmarczak/status/2095369716852256804

    Post summary

    The tweet reports that zero‑click CVE‑2025‑31200/31201 were exploited before the April patch, but it offers no PoC or exploit tool, only noting the vulnerability type and patch status.

    0000052
    72 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSappletvos---
OSapplevisionos---
OSapplewatchos---

Explore more