Rare find

iOS-Attack-Chain-CVE-2025-31200-CVE-2025-31201. CVE-2025-31200 is a zero-day, zero-click RCE in iOS CoreAudio’s AudioConverterService, triggered by a malicious audio file via iMessage/SMS. Exploitation bypassed Blastdoor, enabled kernel escalation (CVE-2025-31201), and allowed token theft until patched in iOS 18.4.1 (Apr 16, 2025).

github.com/JGoyd/iOS-Attack-Chain-CVE-2025-31200-CVE-2025-31201

Vaya's read on this project

Problem, audience, market, and the verdict — sign in to see it.

Updates

No recent activity.