Skip to main content

PSA: iOS 18.4.1 patches two major security vulnerabilities

Apple released iOS 18.4.1, and in addition to CarPlay bug fixes, the update also patches two security vulnerabilities that Apple says were actively exploited in the wild. The security fixes are also included in macOS Sequoia 15.4.1, tvOS 18.4.1, and visionOS 2.4.1.

iOS 18.4.1 security fixes

Apple says it is is aware of reports that both of these security vulnerabilities “may have been exploited in an extremely sophisticated attack against specific targeted individuals.”

Here are the details on the vulnerabilities:

CoreAudio:

  • Impact: Processing an audio stream in a maliciously crafted media file may result in code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.
  • Description: A memory corruption issue was addressed with improved bounds checking.
  • CVE-2025-31200: Apple and Google Threat Analysis Group

RPAC:

  • Impact: An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.
  • Description: This issue was addressed by removing the vulnerable code.
  • CVE-2025-31201: Apple

With these important security fixes in mind, we recommend updating your Apple devices to their newest software versions as soon as possible. This includes iOS 18.4.1, iPadOS 18.4.1, tvOS 18.4.1, macOS 15.4.1, and visionOS 2.4.1. As of right now, Apple hasn’t released a new software update for Apple Watch.

My favorite iPhone accessories:

Follow ChanceThreadsBlueskyInstagram, and Mastodon

FTC: We use income earning auto affiliate links. More.

You’re reading 9to5Mac — experts who break news about Apple and its surrounding ecosystem, day after day. Be sure to check out our homepage for all the latest news, and follow 9to5Mac on Twitter, Facebook, and LinkedIn to stay in the loop. Don’t know where to start? Check out our exclusive stories, reviews, how-tos, and subscribe to our YouTube channel

Comments

Author

Avatar for Chance Miller Chance Miller

Chance is the editor-in-chief of 9to5Mac, overseeing the entire site’s operations. He also hosts the 9to5Mac Daily and 9to5Mac Happy Hour podcasts.

You can send tips, questions, and typos to chance@9to5mac.com.