CVE-2025-31201
Act now ● On CISA KEV — actively exploited
Actively exploited — on the CISA KEV list.
CVSS base
—
EPSS — probability of exploitation (30 days)
13.9%
96.3th percentile
CISA KEV
Listed
Added 2025-04-17 · patch by 2025-05-08
Weakness / dates
—
Published — · modified —
Description
Apple iOS, iPadOS, macOS, and other Apple products contain an arbitrary read and write vulnerability that allows an attacker to bypass Pointer Authentication.