Description
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.
Published: 2025-04-16
Score: 9.8 Critical
EPSS: 14.7% Moderate
KEV: Yes
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker who can read and write arbitrary memory can bypass the pointer authentication mechanism that protects code execution paths on Apple operating systems. This flaw allows the attacker to modify or execute code segments that would normally be protected, potentially enabling the compromise of system integrity and confidentiality. The vulnerability is coded as CWE-1220, indicating a pointer authentication bypass. Based on the description, the likely attack vector requires that the attacker first obtain arbitrary memory read/write capability, which is inferred since the vulnerability explicitly states that such capability is necessary for the bypass.

Affected Systems

The software flaw is present in Apple’s iOS, iPadOS, macOS Sequoia, tvOS, and visionOS releases prior to iOS 18.4.1, iPadOS 18.4.1, macOS 15.4.1, tvOS 18.4.1, and visionOS 2.4.1. Devices running these earlier versions remain susceptible to exploitation.

Risk and Exploitability

The CVSS score of 9.8 classifies the vulnerability as critical, while the EPSS score of 15% indicates a moderate probability that it will be actively exploited. The flaw is cataloged in the CISA KEV list, and reports suggest that it may have been leveraged in a targeted, highly sophisticated attack against certain users on iOS. Because arbitrary memory read/write is required, the attack typically depends on a prior vulnerability that grants such capabilities, which reduces the overall threat distance. Based on the description, the likely attack vector is inferred to involve an initial compromise that provides arbitrary memory access before attempting the pointer authentication bypass.

Generated by OpenCVE AI on July 27, 2026 at 04:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all affected Apple devices to the latest releases that include the patch: iOS 18.4.1 or later, iPadOS 18.4.1 or later, macOS Sequoia 15.4.1, tvOS 18.4.1, and visionOS 2.4.1.
  • Restrict or disable debugging interfaces and developer tools that enable arbitrary memory access, such as JTAG, Xcode Instruments, or insecure APIs that grant read/write privileges.
  • Enforce system integrity protections such as SIP on macOS, apply MDM restrictions, and monitor for abnormal memory operations to detect potential precursor exploits.

Generated by OpenCVE AI on July 27, 2026 at 04:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11381 This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 18.4.1, visionOS 2.4.1, iOS iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.
History

Thu, 18 Jun 2026 04:45:00 +0000

Type Values Removed Values Added
Title Pointer Authentication Bypass via Arbitrary Read/Write on Apple OS Platforms

Wed, 17 Jun 2026 05:15:00 +0000

Type Values Removed Values Added
Title Pointer Authentication Bypass via Arbitrary Read/Write on Apple OS Platforms

Mon, 25 May 2026 17:30:00 +0000

Type Values Removed Values Added
Title Pointer Authentication Bypass via Arbitrary Read/Write Exploit

Tue, 28 Apr 2026 02:45:00 +0000

Type Values Removed Values Added
Title Pointer Authentication Bypass via Arbitrary Read/Write Exploit

Fri, 03 Apr 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 18.4.1, visionOS 2.4.1, iOS iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS. This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.

Mon, 24 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1220
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Nov 2025 20:30:00 +0000


Mon, 03 Nov 2025 19:30:00 +0000

Type Values Removed Values Added
References

Mon, 03 Nov 2025 18:30:00 +0000


Tue, 21 Oct 2025 23:15:00 +0000


Tue, 21 Oct 2025 20:30:00 +0000


Tue, 21 Oct 2025 19:30:00 +0000


Fri, 06 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Fri, 18 Apr 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ipados
Apple iphone Os
Apple macos
Apple tvos
Apple visionos
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple ipados
Apple iphone Os
Apple macos
Apple tvos
Apple visionos

Thu, 17 Apr 2025 23:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2025-04-17'}


Thu, 17 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Apr 2025 18:30:00 +0000

Type Values Removed Values Added
Description This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 18.4.1, visionOS 2.4.1, iOS iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:24:41.543Z

Reserved: 2025-03-27T16:13:58.315Z

Link: CVE-2025-31201

cve-icon Vulnrichment

Updated: 2025-11-03T19:48:19.883Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-16T19:15:54.673

Modified: 2026-06-17T09:10:00.800

Link: CVE-2025-31201

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-27T05:00:04Z

Weaknesses
  • CWE-1220

    Insufficient Granularity of Access Control