iOS 18.4.1 fixes critical CoreAudio and Pointer Authentication vulnerabilities exploited in spyware-like cyberattacks targeting journalists, officials.
April 20, 2025: Apple has rolled out a critical security update—iOS 18.4.1—warning users to update their iPhones immediately. The alert comes amid reports of “extremely sophisticated” attacks targeting specific individuals, including journalists and government officials, using zero-day vulnerabilities.
The two major flaws lie in the CoreAudio framework and Return Pointer Authentication Code (RPAC) system—both essential components for media processing and memory safety on Apple devices.
🔍 What’s at Risk?
- CoreAudio Vulnerability: Could allow arbitrary code execution when a user’s device processes maliciously crafted media files, potentially exposing audio streams and sensitive data.
- RPAC Vulnerability: Allowed hackers to bypass system-level protections, gaining read-write access to iPhones, iPads, Macs, and even Apple TVs and Vision Pro devices.
Apple confirmed these flaws had already been exploited in real-world attacks targeting high-profile individuals.
Also Read: Why Facebook Is Losing Its Relevance: Mark Zuckerberg’s Internal Concerns Revealed
🔧 What’s Fixed in iOS 18.4.1?
- Memory corruption patch in CoreAudio
- Strengthened Pointer Authentication to close bypass gaps
- Bug fix for wireless CarPlay connection issues in select vehicles
Other devices receiving updates:
- iPadOS 18.4.1
- macOS Sequoia 15.4.1
- tvOS 18.4.1
- visionOS 2.4.1
✅ How To Update:
- Open Settings
- Tap General
- Select Software Update
- Tap Download and Install
Ensure your device is connected to Wi-Fi and plugged in or sufficiently charged before beginning the update.
🔐 Why This Matters: Apple rarely uses such strong language in security notices. The active exploitation and targeted nature of these vulnerabilities mark this as one of the most serious iOS threats in recent years.
Cybersecurity experts are urging immediate updates to avoid the risk of surveillance, data theft, or device compromise.
🟩 Tags:
Apple, iOS 18.4.1, CoreAudio vulnerability, RPAC bug, iPhone hack, iOS security update, Apple spyware warning, cybersecurity alert, iPadOS 18.4.1, macOS Sequoia, tech news
