iFixScreens.com

Apple Fixes Two Zero-Day Security Flaws

That Were Actively Exploited in Targeted Attacks on iPhones

Apple Issues Emergency Update Apple releases a critical update to fix two zero-day vulnerabilities exploited in targeted iPhone attacks.

Flaws Exploited in Spy Attacks Apple confirms “extremely sophisticated attacks” targeted specific iPhone users using these flaws.

CoreAudio Bug (CVE-2025-31200) Attackers could run remote code by tricking devices into processing a maliciously crafted audio stream.

RPAC Bug (CVE-2025-31201) This bug lets attackers bypass Pointer Authentication to access device memory and increase attack impact.

Affects All Apple Platforms The flaws impact iOS, iPadOS, macOS Sequoia, visionOS, and tvOS—making it a wide-scale security issue.

Affected Devices List iPhone XS+, iPads (7th gen+), Apple TV (all), Vision Pro, and all current Macs running Sequoia are affected.

Update Versions Released Fixes are available in iOS/iPadOS 18.4.1, macOS 15.4.1, tvOS 18.4.1, and visionOS 2.4.1.

Update Immediately Even though the attacks were targeted, all users should update now to stay protected from future risks.

Fifth Zero-Day Fixed in 2025 This marks Apple’s fifth zero-day patch this year—adding urgency to staying updated.