Close Menu
  • Identity
  • Startups
  • Tech
  • Spanish
What's Hot

Why Wall Street is actually high after the US bombing Iran

Fiserv debuts bank-friendly Stablecoin

Deadline approach to speaker proposals for OpenSSL Conference 2025 held in Prague

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Identity
  • Startups
  • Tech
  • Spanish
Fyself News
Home » Apple patches take advantage of two aggressively exploited iOS flaws used in sophisticated target attacks
Identity

Apple patches take advantage of two aggressively exploited iOS flaws used in sophisticated target attacks

userBy userApril 17, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

April 17, 2025Ravi LakshmananZero Day/Vulnerability

The flaws of actively exploited iOS

On Wednesday, Apple released security updates for iOS, iPados, MacOS Sequoia, TVOS and Visionos, addressing two security flaws that are said to be subject to aggressive exploitation in the wild.

The vulnerabilities in question are listed below –

CVE-2025-31200 (CVSS score: 7.5) – Memory corruption vulnerability in core audio framework that allows code execution when processing audio streams with malicious media files CVE-2025-31201 (CVSS score: 6.8) – Possible to use vulnerabilities in RPAC components that use vulnerabilities in RPAC components.

Cybersecurity

The iPhone manufacturer said it addressed CVE-2025-31200 with improved boundary checks and CVE-2025-31201 by removing vulnerable sections in the code.

Both vulnerabilities are credited to Apple along with the Google Threat Analysis Group (TAG) to report CVE-2025-31200.

Apple said it recognizes that, as in such an advisory, the issue is “exploited in a very sophisticated attack on certain targeted individuals on iOS.”

With the latest developments, Apple has been working on a total of five actively exploited zero-days with its software since its launch this year –

CVE-2025-24085 (CVSS score: 7.8) – Wasted bug in core media components that could allow malicious applications that can increase privileges by malicious applications already installed on the device CVE-2025-24200 (CVSS score: 4.6) – Issue authorization of accessibility components that could hinder accessibility components Attack CVE-2025-24201 (CVSS score: 7.1) – Issue out-of-bounds issues with WebKit components that could be exploited to use malicious web content to get out of the web content sandbox

Cybersecurity

Updates are available on the following devices and operating systems –

I’m running iOS 18.4.1 and iPad 18.4.1 – iPhone XS or later, iPad Pro 13 inch, iPad Pro 13.9 inch 3rd generation or later, iPad Pro 11 inch 1st generation or later, iPad Air 3rd Generation and then iPad 7th generation or later, iPad Mini 5th Generation and Later Macos appper sequos adques hde seques hde seques aspects 15.4.1 -MAC. TV 4K (All Models) Visionos 2.4.1 – Apple Vision Pro

In light of aggressive exploitation, users are encouraged to update their devices to the latest version to prevent risk.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleHead Start Start Rag will fund nearly $1 billion this year, causing preschool closures
Next Article Russia-Ukraine War: List of Major Events, Day 1,148 | News of the Russian-Ukraine War
user
  • Website

Related Posts

DHS warns Proilan hackers who are likely to target US networks after Iran’s nuclear attack

June 23, 2025

XDIGO Malware exploits Windows LNK flaws in Eastern European government attacks

June 23, 2025

How AI-enabled workflow automation helps SOCs reduce burnout

June 23, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Why Wall Street is actually high after the US bombing Iran

Fiserv debuts bank-friendly Stablecoin

Deadline approach to speaker proposals for OpenSSL Conference 2025 held in Prague

Description of MCI UK and Meet & Potato: What was the merger like?

Trending Posts

Sana Yousaf, who was the Pakistani Tiktok star shot by gunmen? |Crime News

June 4, 2025

Trump says it’s difficult to make a deal with China’s xi’ amid trade disputes | Donald Trump News

June 4, 2025

Iraq’s Jewish Community Saves Forgotten Shrine Religious News

June 4, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Deadline approach to speaker proposals for OpenSSL Conference 2025 held in Prague

AI Startup Snowcap raises $23 million in funding to build a superconducting chip that could surpass Nvidia

BitMart’s R0AR List: $1R0R Makes CEX’s Debut

Gap 3 Partners FZCO will become Dubai’s first regulated virtual asset investment advisor with an operational license from VARA

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.