Apple on Wednesday shipped out‑of‑band operating system updates to fix a pair of security bugs the company says were already exploited in “extremely sophisticated” attacks against a small number of iOS targets.
The vulnerabilities, tagged as CVE-2025-31200 and CVE-2025-31201, are described as code execution and mitigation bypass issues that affect Apple’s iOS, iPadOS and macOS platforms.
Apple said it was aware of a report that both flaws were part of high-end attacks against specific target iPhones.
Here’s Apple’s description of the software defects:
CoreAudio (CVE-2025-31200) — Processing an audio stream in a maliciously crafted media file may result in code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS. A memory corruption issue was addressed with improved bounds checking. The company said Google’s TAG (Threat Analysis Group) reported the issue.
RPAC (CVE-2025-31201) — An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS. This issue was addressed by removing the vulnerable code.
Pointer Authentication is a security feature in certain ARM architecture that provides a cryptographically strong guarantee about the likelihood that a pointer has been tampered with.
The vulnerabilities were also patched on all machines running macOS Sequoia but Apple notes that the reported exploitation has only happened on a limited number of iPhones.
As is customary, Apple did not share details or IOCs on the in-the-wild exploitation.
Related: Apple Suddenly Drops NSO Group Spyware Lawsuit
Related: Microsoft Patches 125 Flaws, Including Exploited CLFS Zero-Day
Related: Rapid7 Reveals RCE Path in Ivanti VPNs After Silent Patch Debacle
Related: Apple Pulls Advanced Data Protection in UK Amid Backdoor Demand
Related: Apple USB Restricted Mode in ‘Extremely Sophisticated’ Hack