Hack

Security researchers share PoC for CVE-2025-31200, a security vulnerability patched in iOS 18.4.1

iPhone hacked matrix.

In iOS & iPadOS 18.4.1, Apple patched CVE-2025-31200, which is a CoreAudio security vulnerability patch that could have enabled arbitrary code execution in the userspace process responsible for processing the malicious file. Apple was made aware of instances in which this vulnerability may have been used against specifically targeted individuals and consequently patched it with improved bounds checking.

PureKFD device toolbox version 5.3 released with improvements for KFD exploit users

PureKFD.

PureKFD is an iOS toolbox for non-jailbroken devices that supports various versions of iOS & iPadOS ranging from 14.0 through 18.0/18.1 beta 4. While it previously only supported firmware versions that were susceptible to the Kernel File Descriptor (KFD) exploit, that all changed recently when the toolbox added support for the more recent SparseRestore exploit starting with version 6.

Developers use Ian Beer’s CVE-2025-24203 write-up to bring MacDirtyCow-like tweaks to newer firmware

MDC0 and dirtyZero apps.

In case you didn’t already know, there’s a new kernel exploit out in the wild that renowned Google Project Zero security researcher Ian Beer recently published a writeup about. CVE-2025-24203, which is being referred to by the iPhone & iPad hacking community as dirtyZero or mdc0, is a kernel exploit that allows for certain system customizations akin to what the MacDirtyCow exploit was once capable of on supported firmware.