Urgent Alert: Apple Releases Critical iPhone Update to Address Zero-Day Vulnerabilities
If you haven’t already updated your iPhone to the latest iOS, it’s important to do so promptly. On Wednesday, April 16, Apple released iOS 18.4.1. This update addresses two critical zero-day vulnerabilities that have been exploited by hackers. “Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS,” the company stated in an announcement regarding each of the two exploits.
According to Apple, the two vulnerabilities affect Core Audio (CVE-2025-31200) and Return Pointer Authentication Code, commonly referred to as RPAC (CVE-2025-31201). Core Audio is an API that Apple employs for sound processing across its operating systems. The CVE-2025-31200 vulnerability allowed a malicious actor to execute code on the device while processing an audio stream from a “maliciously crafted media file.” In contrast, Return Pointer Authentication Code is a security feature designed to prevent attackers from manipulating existing code for harmful purposes. The exploit identified as CVE-2025-31201 permits a threat actor with “arbitrary read and write capability” to bypass this Pointer Authentication security measure.
These vulnerabilities affect not only the iPhone but also a range of other Apple devices, including certain iPad models, Apple TV, Apple Vision Pro, and Macs running macOS Sequoia. Apple has released updates for each of these devices’ operating systems to mitigate the risks associated with these exploits.
