CVE-2025-31201CRITICAL 9.8CISA KEVEPSS p95.7%

CVE-2025-31201Apple Multiple Products Arbitrary Read and Write Vulnerability

Apple / Multiple Products

Description

Apple iOS, iPadOS, macOS, and other Apple products contain an arbitrary read and write vulnerability that allows an attacker to bypass Pointer Authentication.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS12.36% probability of exploitation · percentile 95.7% · 2026-06-18T12:00:27Z
Published2025-04-16
Last modified2026-04-03

CISA KEV entry

Added to KEV: 2025-04-17

Underlying weaknesses· 1

CWE-1220

References

  1. https://support.apple.com/en-us/122282
  2. https://support.apple.com/en-us/122400
  3. https://support.apple.com/en-us/122401
  4. https://support.apple.com/en-us/122402
  5. http://seclists.org/fulldisclosure/2025/Apr/26
  6. http://seclists.org/fulldisclosure/2025/Jun/14
  7. http://seclists.org/fulldisclosure/2025/Oct/0
  8. http://seclists.org/fulldisclosure/2025/Oct/3

1

TypeTargetConfidenceTier
WeaknessInsufficient Granularity of Access Controlcwe-12200%live

(incoming)1

TypeTargetConfidenceTier
KEVEntryApple Multiple Products Arbitrary Read and Write Vulnerabilitykev-cve-2025-312010%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Apple Multiple Products Memory Corruption Vulnerability
CVE
Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability
CVE
Apple Multiple Products Improper Locking Vulnerability
CVE
Apple iOS and macOS Out-of-Bounds Write Vulnerability
CVE
Apple Multiple Products Use-After-Free Vulnerability
CVE
CVE-2022-42827
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.