On Wednesday, Apple released urgent operating system updates to address two security vulnerabilities that had already been exploited in highly sophisticated attacks targeting a few iOS users.
The vulnerabilities CVE-2025-31200 and CVE-2025-31201 allow for code execution and bypass mitigation on Apple’s iOS, iPadOS, and macOS platforms.
By infosecbulletin
/ Friday , October 9 2026
There was a rise in scanning and remote code execution attempts on video surveillance devices in Ukraine from September 21...
Read More
By infosecbulletin
/ Thursday , October 8 2026
The FBI and U.S. Secret Service released a joint warning about cybersecurity. The warning said that the FortiBleed campaign is...
Read More
By infosecbulletin
/ Wednesday , October 7 2026
Bangladesh's digital payments system remains severely disrupted after a technology conflict forces core card and interbank services offline for millions...
Read More
By infosecbulletin
/ Tuesday , October 6 2026
Atlassian has fixed CVE-2026-21589, a serious flaw in Atlassian Data Center with a score of 9.3. This bug allows an...
Read More
By infosecbulletin
/ Monday , October 5 2026
Citrix has put out emergency security updates for a NetScaler SAML flaw that hackers are using. Known as CVE-2026-88779, this...
Read More
By infosecbulletin
/ Monday , October 5 2026
Hackers got into the identity and access management system at the Technical University of Denmark (DTU) and downloaded a lot...
Read More
By infosecbulletin
/ Sunday , October 4 2026
Microsoft's official X account was taken over to promote an unapproved Clippy-themed cryptocurrency. The tech giant’s X account, with 13...
Read More
By infosecbulletin
/ Saturday , October 3 2026
CPanel has put out security updates to fix three problems in cPanel & WHM. These problems could let attackers take...
Read More
By infosecbulletin
/ Friday , October 2 2026
Nearly 100,000 Bee Cheng Hiang customers had their email addresses leaked when an employee used an AI tool to generate...
Read More
By infosecbulletin
/ Thursday , October 1 2026
Hackers to exploit a flaw in Zimbra mail servers that are connected to the Internet. They send special emails that...
Read More
Apple acknowledged a report indicating that both flaws were exploited in targeted attacks on specific iPhones.
Here’s Apple’s description of the software defects:
CoreAudio (CVE-2025-31200) — Processing an audio stream in a malicious media file could lead to code execution. Apple is aware of reports that this vulnerability may have been exploited in a sophisticated attack on specific iOS users. A memory corruption problem was fixed with better bounds checking, as reported by Google’s Threat Analysis Group (TAG).
RPAC (CVE-2025-31201) — An attacker with read and write access could potentially bypass Pointer Authentication. Apple has been informed of a report suggesting this issue may have been exploited in a sophisticated attack targeting specific individuals on iOS. The problem has been fixed by removing the vulnerable code.
Pointer Authentication is a security feature in some ARM architectures that ensures a pointer hasn’t been tampered with through cryptographic methods.
Vulnerabilities on macOS Sequoia have been fixed, but Apple reports that exploitation has been limited to a few iPhones. As usual, Apple did not provide details or IOCs about these exploits.
Oracle Released Patched for 378 flaws for April 2025