Vulnerability record · CVE-2025-31200 · published 16 April 2025
CVE-2025-31200: Apple OS media parsing memory corruption allows code execution
Apple · Macos
A memory corruption flaw in Apple's audio stream processing was fixed with improved bounds checking across iOS, iPadOS, macOS, tvOS, visionOS and watchOS. Processing a maliciously crafted media file can lead to code execution, and Apple states the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS versions before 18.4.1.
Description
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1, watchOS 11.5. Processing an audio stream in a maliciously crafted media file may result in code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS released before iOS 18.4.1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, CISA KEV listing with a near-term due date, and vendor confirmation of exploitation in targeted attacks make this a top remediation priority.
What it is
A memory corruption flaw in Apple's audio stream processing was fixed with improved bounds checking across iOS, iPadOS, macOS, tvOS, visionOS and watchOS. Processing a maliciously crafted media file can lead to code execution, and Apple states the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS versions before 18.4.1.
Impact
An attacker can achieve code execution in the context of the affected media-processing component, with the CVSS vector indicating high confidentiality, integrity and availability impact. Given the targeted nature reported by Apple, the practical gain is device compromise of selected individuals rather than mass exploitation.
Attack surface
Reached by processing an audio stream in a maliciously crafted media file; the CVSS vector is network, no privileges and no user interaction, though in practice delivery requires the victim to handle the crafted media. No authentication is required by the vector.
Exploitation
Listed in CISA KEV with a 2025-05-08 remediation due date, and Apple states the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals. EPSS 30-day probability is 0.18593 (97th percentile), and references include exploit-tagged links, though two of those are marked broken.
What to do
- Update to iOS 18.4.1, iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1 and watchOS 11.5 per Apple advisories.
- Treat unpatched Apple devices as exposed and prioritize the KEV remediation due date of 2025-05-08.
- Restrict or disable automatic processing of untrusted media files where feasible, and avoid opening media from unknown senders.
- For high-risk individuals, consider Lockdown Mode and tighter controls on inbound media delivery channels.
- Track vendor advisories for any further updates covering older OS branches.
Detection
- Hunt for crashes or abnormal terminations in media/audio parsing processes (mediaserverd, coreaudiod and similar) on Apple endpoints.
- Monitor for exploitation indicators around crafted media file delivery, such as unusual attachments or links sent to targeted users.
- Review endpoint telemetry for unexpected child processes or code execution originating from media handling components.
- Correlate device OS build versions against the fixed releases to find unpatched assets.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-31200 to the Known Exploited Vulnerabilities catalog on 17 April 2025 as "Apple Multiple Products Memory Corruption Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 8 May 2025.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2025-31200 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-31200), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.