CVE-2025-31201Active Exploitation(apple / ipados)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.

4.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-05-08. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-1220

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • tvos

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-09-03)
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
ipadosiphone_osmacostvosvisionos

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-02-01: 1Mentions · 2026-02-17: 1Mentions · 2026-08-14: 1Mentions · 2026-09-03: 2Active Exploitation · 2026-09-03: 2Patch / Workaround · 2026-08-14: 1Patch / Workaround · 2026-09-03: 1Technical Details · 2026-02-01: 102-0102-1708-1409-03
Signal classification4 categories
Active Exploitation
240.0%
Disclosure
120.0%
General
120.0%
Patch
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-011
Disclosure1
2026-02-171
General1
2026-08-141
Patch1
2026-09-032
Active Exploitation2
Full discourse5 posts
  • Bill Marczak@billmarczak
    Active Exploitation

    Seems like CVE-2025-31200 and CVE-2025-31201 were NSO Group! Most recent zero-click chain that appears to be attributable to them https://support.apple.com/en-us/122282 (Ref: https://citizenlab.ca/research/pegasus-spyware-infection-of-serbian-activist/)

    Post summary

    The post attributes CVE-2025-31200 and CVE-2025-31201 to NSO Group’s latest zero‑click chain, indicating active exploitation, but offers no PoC, exploit code, or patch details.

    13722009918.3K
    12.9K followersView on X
  • ︎@0xocdsec
    Disclosure

    "... CVE-2025-31201 (PAC bypass vulnerability) Combined with CVE-2025-31200, it forms a zero-interaction attack chain of "user-mode RCE → kernel privilege escalation → persistence", requiring no further interaction. triggered simply by clicking and receiving an iMessage ...."

    Post summary

    The text discloses a zero‑interaction attack chain involving CVE‑2025‑31201 and CVE‑2025‑31200, describing user‑mode RCE and kernel privilege escalation, but offers no evidence of active exploitation or remediation.

    11020467
    4.3K followersView on X
  • (˶ᵔ ᵕ ᵔ˶)@minjusjellyfish
    Patch

    @imperfectforgru @THEEgrandeee Be sure u r using the newest iOS 18 update at least because CVE-2025-31201

    Post summary

    The tweet urges users to update to iOS 18 to apply the patch for CVE‑2025‑31201.

    000101.5K
    65 followersView on X
  • Num1SnoopyFan@Num1SnoopyFan
    General

    @speedyfriend433 @asert17240 CVE-2025-31201 is one i think

    Post summary

    The text only mentions the CVE identifier without any additional context or details.

    0001079
    12 followersView on X
  • Smart Global Technologies@inviolableio
    Active Exploitation

    CVE-2025-31200 & CVE-2025-31201 — the zero-click chain Apple patched this year — now appears attributable to NSO Group (Citizen Lab). Patching closes the door. It can't tell you if the attack landed before you updated. Forensic analysis can. https://inviolable.online

    Post summary

    The post highlights that Apple’s zero‑click CVEs 2025‑31200/01, now associated with NSO Group, were exploited in the wild, but Apple’s patch is available and forensic analysis can confirm prior usage.

    0000055
    72 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSappletvos---
OSapplevisionos---

Explore more