Apple has released urgent security updates to fix two zero-day vulnerabilities that were used in a "highly sophisticated attack" against specific iPhone targets.
See also: RansomEXX ransomware group used Windows CLFS zero-day

The two vulnerabilities are located in CoreAudio (CVE-2025-31200) and RPAC (CVE-2025-31201), affecting iOS, macOS, tvOS, iPadOS , and visionOS.
The CVE-2025-31200 vulnerability in CoreAudio was discovered by Apple and Threat Analysis . It can be exploited by processing an audio stream within a maliciously crafted media file, allowing remote code execution on the device.
Apple also fixed the CVE-2025-31201 vulnerability, which it discovered. This is a bug in RPAC that allows attackers with read or write permissions to bypass Pointer Authentication (PAC), an iOS security feature that protects against memory vulnerabilities
Apple has not provided further details on how the vulnerabilities were exploited in the attacks. Both vulnerabilities were fixed in iOS 18.4.1, iPadOS 18.4.1, tvOS 18.4.1, macOS Sequoia 15.4.1 , and visionOS 2.4.1.
See also: Apple warns of three zero-day flaws

The list of devices affected by these zero-day vulnerabilities is extensive, covering both older and newer models:
- iPhone XS and newer
- iPad Pro 13-inch, iPad Pro 13.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later
- iPad Air 3rd generation and newer
- iPad 7th generation and newer
- iPad mini 5th generation and newer
- macOS Sequoia
- Apple TV HD and Apple TV 4K (all models)
- Apple Vision Pro
While these zero-day vulnerabilities have been exploited in highly targeted attacks, users are strongly advised to install the updates as soon as possible. With the latest two vulnerabilities, Apple has now patched a total of five zero-day vulnerabilities since the beginning of the year: the first in January (CVE-2025-24085), the second in February (CVE-2025-24200), and the third in March (CVE-2025-24201).
See also: EncryptHub exploited zero-day vulnerability in Microsoft Management Console
The continued emergence and exploitation of zero-day vulnerabilities shows how important it is to keep our devices fully updated. While these attacks may target a limited number of users — such as journalists, activists, or high-profile individuals — these vulnerabilities can potentially be exploited on a wider scale if not patched in a timely manner.
Source: bleepingcomputer
