{"id":"CVE-2025-31200","title":"Memory corruption in CoreAudio via crafted media file","summary":"A maliciously crafted media file processed by Apple CoreAudio can trigger heap corruption leading to remote code execution. Reported as exploited in the wild against targeted individuals.","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":"CWE-787","vendor":"Apple","product":"CoreAudio","platforms":["iOS","iPadOS","macOS","tvOS","visionOS"],"affected":["iOS < 18.4.1","macOS Sequoia < 15.4.1"],"patched":["iOS 18.4.1","macOS Sequoia 15.4.1"],"exploited":true,"zeroDay":true,"epss":0.18751,"epssPercentile":0.9715,"kev":true,"kevDateAdded":"2025-04-17","kevDueDate":"2025-05-08","kevRansomware":false,"source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-31200","references":[{"url":"https://support.apple.com/en-us/122282","label":"Apple security advisory"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-31200","label":"NVD"}],"tags":["apple","rce","in-the-wild","media-parsing","kev","exploit-available"],"exploits":{"github":4,"githubRepos":["https://github.com/zhuowei/apple-positional-audio-codec-invalid-header","https://github.com/JGoyd/iOS-Attack-Chain-CVE-2025-31200-CVE-2025-31201","https://github.com/serundengsapi/CVE-2025-31200-iOS-AudioConverter-RCE"],"checkedAt":"2026-09-24T07:52:44.639Z"},"exploitAvailable":true,"slug":"CVE-2025-31200","body":"## Overview\n\nA memory corruption issue exists in the **CoreAudio** media parsing path. Processing\nan audio stream embedded in a maliciously crafted media file can corrupt heap memory\nand, when chained, lead to arbitrary code execution in the context of the media\nservice.\n\nApple states this issue \"may have been exploited in an extremely sophisticated attack\nagainst specific targeted individuals.\"\n\n## Impact\n\n- **Remote code execution** with user interaction (open/preview of the media file).\n- Affects the wide CoreAudio-backed surface: Messages, Safari preview, Mail, AirDrop\n  previews, and any app that decodes audio via the system framework.\n\n## Affected versions\n\n| Platform | Affected | Fixed |\n| --- | --- | --- |\n| iOS / iPadOS | < 18.4.1 | 18.4.1 |\n| macOS Sequoia | < 15.4.1 | 15.4.1 |\n| tvOS | < 18.4.1 | 18.4.1 |\n| visionOS | < 2.4.1 | 2.4.1 |\n\n## Detection\n\nNo reliable host-side IOC published. Recommended signals:\n\n- Crash logs referencing `CoreAudio` / `AudioCodecs` with `EXC_BAD_ACCESS`.\n- Inbound media files from untrusted contacts immediately preceding a media-service\n  crash loop.\n\n## Remediation\n\n1. Update to the fixed build on every affected platform immediately.\n2. For high-risk users, enable **Lockdown Mode**, which constrains media auto-preview.\n3. Treat unsolicited media attachments as hostile until patched.\n\n## References\n\n- Apple security advisory: <https://support.apple.com/en-us/122282>\n- NVD: <https://nvd.nist.gov/vuln/detail/CVE-2025-31200>","depth":"abyssal","depthScore":70,"depthScoreParts":{"impact":41.3,"likelihood":3.8,"exploitation":25,"ransomware":0},"changes":[{"seq":4435,"id":"CVE-2025-31200","ts":1788887179062,"field":"exploit_available","old":"false","new":"true"},{"seq":3318,"id":"CVE-2025-31200","ts":1788886298141,"field":"exploit_available","old":"true","new":"false"},{"seq":2173,"id":"CVE-2025-31200","ts":1788882968086,"field":"exploit_available","old":"false","new":"true"},{"seq":1202,"id":"CVE-2025-31200","ts":1788882367310,"field":"exploit_available","old":"true","new":"false"},{"seq":316,"id":"CVE-2025-31200","ts":1788881814216,"field":"exploit_available","old":"false","new":"true"}]}