Apple Patches Two Actively Exploited iOS Flaws Used in Sophisticated Targeted Attacks
Summary: Security Officer Comments: Link(s):
Apple released security advisories on Wednesday for iOS, iPadOS, macOS Sequoia, tvOS, and visionOS to address two vulnerabilities, CVE-2025-31200 and CVE-2025-31201, that have been observed being actively exploited in the wild. CVE-2025-31200 and CVE-2025-31201 carry CVSS scores of 7.5 and 6.8, respectively. CVE-2025-31200 was addressed with improved bounds checking, and CVE-2025-31201 was addressed by removing a vulnerable section of the code. Google Threat Analysis Group (TAG) was credited with reporting CVE-2025-31200. The attacks where Apple observed these flaws were "exploited in an extremely sophisticated attack against specific targeted individuals on iOS."
Five actively-exploited zero-day vulnerabilities in Apple software this year:
Counting this new development, Apple has already had to address 5 actively exploited zero-days in its software this year. Due to the active exploitation risk, Apple has advised users to update all devices to their latest version to help mitigate the risk of these attacks. A robust patch management policy is a cornerstone of a strong security posture and good IT hygiene. Systematically addressing vulnerabilities by ensuring systems are up-to-date significantly reduces the attack surface and helps maintain the availability of operations while complying with government regulations.
Suggested Corrections:
Updates available:
https://thehackernews.com/2025/04/apple-patches-two-actively-exploited.html