Article Details
Scrape Timestamp (UTC): 2025-04-17 03:40:23.480
Source: https://thehackernews.com/2025/04/apple-patches-two-actively-exploited.html
Original Article Text
Click to Toggle View
Apple Patches Two Actively Exploited iOS Flaws Used in Sophisticated Targeted Attacks. Apple on Wednesday released security updates for iOS, iPadOS, macOS Sequoia, tvOS, and visionOS to address two security flaws that it said have come under active exploitation in the wild. The vulnerabilities in question are listed below - The iPhone maker said it addressed CVE-2025-31200 with improved bounds checking and CVE-2025-31201 by removing the vulnerable section of code. Both the vulnerabilities have been credited to Apple, along with Google Threat Analysis Group (TAG) for reporting CVE-2025-31200. Apple, as is typically the case with such advisories, said it's aware that the issues have been "exploited in an extremely sophisticated attack against specific targeted individuals on iOS." With the latest development, Apple has addressed a total of five actively exploited zero-days in its software since the start of the year - The updates are available for the following devices and operating systems - In light of active exploitation, users are advised to update their devices to the latest version to safeguard against risks.
Daily Brief Summary
Apple has released security updates for iOS, iPadOS, macOS Sequoia, tvOS, and visionOS to patch two actively exploited vulnerabilities.
The vulnerabilities, identified as CVE-2025-31200 and CVE-2025-31201, were fixed by improving bounds checking and removing vulnerable code sections respectively.
These security flaws were exploited in highly sophisticated attacks targeting specific individuals, demonstrating advanced exploitation techniques.
Google Threat Analysis Group (TAG) reported one of these vulnerabilities, highlighting the collaborative efforts in cybersecurity.
Users of affected Apple devices are urged to update their systems immediately to protect against these security risks.
This incident marks the fifth instance of zero-day vulnerabilities in Apple's software being actively exploited since the beginning of the year.
Persistent cyber threats emphasize the ongoing need for vigilance and regular updates in the tech industry to safeguard user data and privacy.