{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2025-31201",
  "revision": 1,
  "title": "Apple platforms — pointer authentication bypassed",
  "summary": "An attacker who can already read and write memory on iOS, iPadOS, macOS, tvOS or visionOS can get past the pointer authentication meant to stop exactly that step. Apple removed the vulnerable code rather than repairing it.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 9.8,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.13973,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": true,
    "attack_complexity": "low",
    "kev_added": "2025-04-17",
    "prerequisites": "The attacker must already be able to read and write memory on the device."
  },
  "remediation": {
    "patch_available": true,
    "fixed_in": [
      "iOS 18.4.1",
      "iPadOS 18.4.1",
      "macOS Sequoia 15.4.1",
      "tvOS 18.4.1",
      "visionOS 2.4.1"
    ]
  },
  "kill_chain": "defense_evasion",
  "recommended_action": "Update to iOS and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1 or visionOS 2.4.1 now; it is the second half of a targeted chain.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2025-31201",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2025-31201",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2025-31201",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31201",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://support.apple.com/en-us/122282"
    },
    {
      "type": "vendor_advisory",
      "url": "https://support.apple.com/en-us/122400"
    },
    {
      "type": "vendor_advisory",
      "url": "https://support.apple.com/en-us/122401"
    }
  ],
  "published_at": "2025-04-16T19:15:54.673Z",
  "issued_at": "2026-09-24T12:03:01.274Z",
  "tags": [
    "apple",
    "ios",
    "macos",
    "pointer-authentication",
    "targeted-attack",
    "kev"
  ]
}
