CVE-2025-31200High· 7.5▾ Abyssal⚠ Exploited in the wild0dayPoC availableA maliciously crafted media file processed by Apple CoreAudio can trigger heap corruption leading to remote code execution. Reported as exploited in the wild against targeted individuals.
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 41.3 · likelihood 3.7 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Federal remediation due May 8, 2025
21%
21% → 22%
4 GitHub repos
Added to the CISA catalog on Apr 17, 2025. Federal remediation due May 8, 2025. View catalog ↗
A memory corruption issue exists in the CoreAudio media parsing path. Processing an audio stream embedded in a maliciously crafted media file can corrupt heap memory and, when chained, lead to arbitrary code execution in the context of the media service.
Apple states this issue "may have been exploited in an extremely sophisticated attack against specific targeted individuals."
| Platform | Affected | Fixed |
|---|---|---|
| iOS / iPadOS | < 18.4.1 | 18.4.1 |
| macOS Sequoia | < 15.4.1 | 15.4.1 |
| tvOS | < 18.4.1 | 18.4.1 |
| visionOS | < 2.4.1 | 2.4.1 |
No reliable host-side IOC published. Recommended signals:
CoreAudio / AudioCodecs with EXC_BAD_ACCESS.Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2022-0995High· 7.8An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem
CVE-2020-1054High· 7.0An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory
CVE-2021-4034High· 7.8A local privilege escalation vulnerability was found on polkit's pkexec utility
CVE-2022-21882High· 7.0Win32k Elevation of Privilege Vulnerability
CVE-2018-8174High· 7.5A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1…
CVE-2021-1732High· 7.8Windows Win32k Elevation of Privilege Vulnerability