2025-04-17 05:16:00
www.zdnet.com

Apple has rolled out its latest iPhone update, iOS 18.4.1. Though minor, you’ll want to install the update as it patches a CarPlay glitch and several dangerous security flaws.
Also: The best VPN services (and how to choose the right one for you)
After the release of iOS 18.4 earlier this month, many iPhone and CarPlay users started complaining of random connection problems and other hiccups. Some people reported that CarPlay would disconnect and reconnect, while others revealed that the CarPlay screen would appear blank. In its description of iOS 18.4.1, Apple said the update “addresses a rare issue that prevents wireless CarPlay connection in certain vehicles.”
With that bug hopefully solved, let’s move on to the more urgent matter of security vulnerabilities. The latest update deals with two serious flaws already used in targeted attacks.
Also: Just installed iOS 18.4? Changing these 3 features made my iPhone much better to use
The first flaw, CVE-2025-31200, is described as “processing an audio stream in a maliciously crafted media file may result in code execution.” That process refers to an attacker who uses Apple’s CoreAudio framework to create a media file containing malware. Any iPhone user who launches the file would trigger the malicious code, allowing the attacker to access the device.
This vulnerability may have been exploited in an “extremely sophisticated attack against specific targeted individuals on iOS,” according to Apple. To squash this bug, the company fixed a memory corruption issue, a problem in which a program can modify memory to execute malicious code.
The second flaw, CVE-2025-31201, means “an attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.” Pointer Authentication is a type of protection designed to thwart attacks that try to corrupt system memory. With the flaw exploited, an attacker can gain access to memory by skirting past this protection. That means they can then run malicious code or steal sensitive data.
This vulnerability was also found to have been used in attacks against targeted individuals. Apple fixed the glitch by removing the vulnerable code.
Also: iOS 18.4 is a bigger iPhone upgrade than I expected: Try my 5 favorite features
Typically, these flaws would be used only in highly targeted attacks against political figures, journalists, and other prominent individuals. However, the vulnerabilities pose serious threats to the security of Apple devices, so all users should install them.
The CarPlay fix is only for iOS, but the two security patches apply to other Apple products. As such, Apple has updated iPadOS, MacOS, TVOS, and VisionOS. If you use any of those operating systems and the associated devices, download and install the latest update.
Keep your entertainment at your fingertips with the Amazon Fire TV Stick 4K! Enjoy streaming in 4K Ultra HD with access to top services like Netflix, Prime Video, Disney+, and more. With an easy-to-use interface and voice remote, it’s the ultimate streaming device, now at only $21.99 — that’s 56% off!
With a 4.7/5-star rating from 43,582 reviews and 10K+ bought in the past month, it’s a top choice for home entertainment! Buy Now for $21.99 on Amazon!
Help Power Techcratic’s Future – Scan To Support
If Techcratic’s content and insights have helped you, consider giving back by supporting the platform with crypto. Every contribution makes a difference, whether it’s for high-quality content, server maintenance, or future updates. Techcratic is constantly evolving, and your support helps drive that progress.
As a solo operator who wears all the hats, creating content, managing the tech, and running the site, your support allows me to stay focused on delivering valuable resources. Your support keeps everything running smoothly and enables me to continue creating the content you love. I’m deeply grateful for your support, it truly means the world to me! Thank you!
BITCOIN bc1qlszw7elx2qahjwvaryh0tkgg8y68enw30gpvge Scan the QR code with your crypto wallet app |
DOGECOIN D64GwvvYQxFXYyan3oQCrmWfidf6T3JpBA Scan the QR code with your crypto wallet app |
ETHEREUM 0xe9BC980DF3d985730dA827996B43E4A62CCBAA7a Scan the QR code with your crypto wallet app |
Please read the Privacy and Security Disclaimer on how Techcratic handles your support.
Disclaimer: As an Amazon Associate, Techcratic may earn from qualifying purchases.