Apple fixes two zero-days exploited in targeted iPhone attacks

Apple fixes two zero-days exploited in targeted iPhone attacks
Summary: Apple has released emergency security updates to address two zero-day vulnerabilities in multiple operating systems that were used in sophisticated attacks on targeted iPhones. The vulnerabilities, CVE-2025-31200 in CoreAudio and CVE-2025-31201 in RPAC, affect a wide range of Apple devices. Users are urged to update their devices immediately to safeguard against potential exploitation.

Affected: Apple iOS, macOS, tvOS, iPadOS, visionOS devices

Keypoints :

  • Two zero-day vulnerabilities (CVE-2025-31200 and CVE-2025-31201) were found in CoreAudio and RPAC.
  • The vulnerabilities allow remote code execution and bypass of iOS security features, impacting various device models.
  • Apple has fixed five zero-days this year, highlighting a significant security risk for users.

Source: https://www.bleepingcomputer.com/news/security/apple-fixes-two-zero-days-exploited-in-targeted-iphone-attacks/

Views: 23