Apple tells millions of iPhone users to update their devices NOW after 'extremely sophisticated attack'

Apple users are being urged to update their devices after the company was hit by an ‘extremely sophisticated attack’.

The tech giant said the hack was used against ‘specific targeted individuals’ but shared no further details.

Instead, it is urging millions of iPhone, iPad, Mac and other iOS users to download a new security patch that fixes the flaw.

Users of iPhone and iPad who have automatic updates enabled will find that the patch has already been automatically installed. For those who do not have automatic updates or disabled it, they will need to manually go to their device settings and download the fixes for both iOS 18.4.1 and iPadOS 18.4.1.

The devices affected by these vulnerabilities range from older to newer models. This includes iPhone XS and later models, iPad Pro 13-inch and later, iPad Pro 13.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, iPad mini 5th generation and later, macOS Sequoia, Apple TV HD and Apple TV 4K (all models), and Apple Vision Pro.

The potential for a devastating cyber attack stemmed from two flaws discovered by Apple and the Google Threat Analysis team. 

These vulnerabilities are known as zero-day vulnerabilities, which are weaknesses in software that are completely unknown to the vendor at the time of discovery. This means that there is no existing patch to fix the flaw when it is first identified, allowing hackers the opportunity to exploit these vulnerabilities.

In this case, the zero-days affected the iPhone’s CoreAudio and Pointer Authentication software (RPAC), allowing hackers to gain access to a phone through vulnerable programs.

Apple users are being urged to update their devices after the company was hit by an 'extremely sophisticated attack' (stock image)

Apple users are being urged to update their devices after the company was hit by an ‘extremely sophisticated attack’ (stock image)

Specifically, Apple and Google found a zero-day flaw in CoreAudio called CVE-2025-31200.

CoreAudio is a low-level program in Apple’s operating systems (iOS, iPadOS, macOS, tvOS, and watchOS) designed to handle audio processing, playback, and recording.

It also provides developers with tools to manage audio data efficiently and interact with audio hardware.

The flaw could have been exploited by processing an audio stream using a maliciously crafted media file which would execute a ‘remote code’ on the device.

Simply put, the remote code allowed a hacker can send a bad audio file (like a fake MP3) to Apple devices, and when your phone or computer tries to play or open it, the file tricks the system into running the hacker’s secret instructions.

Those instructions act like a computer virus, letting the hacker take over the iPhone and steal your info.

The second zero-day flaw, CVE-2025-31201, was found in a program called RPAC, allowing attackers to create their own bypass codes to avoid Pointer Authentication (PAC) – an iOS security feature that protects against memory vulnerabilities.

Without the new security updates, hackers could sneak bad code into an iPhone, iPad, or Mac through PAC.

If someone with access to your device’s memory (like through a shady app or another hack) used this flaw, they could trick the system into running their harmful code.

This could also let them take over the device, steal photos or passwords, or damage the phone completely.

Apple have discovered 5 different zero-day flaws that required an immediate security update since the start of 2025

Apple have discovered 5 different zero-day flaws that required an immediate security update since the start of 2025

BleepingComputer noted that there have now been five zero-day vulnerabilities discovered in 2025.

All of them were fixed as soon as users downloaded the latest security updates from Apple.

Cybersecurity experts told DailyMail.com that one of the best things an iPhone user can do to protect themselves from hackers is regularly update their device’s software.

That means checking the phone’s updates screen for the latest patches available or changing the device’s settings to automatically install these patches when Apple releases them.

You May Also Like
When Will ‘The Chosen: Last Supper’ Hit Streaming? ‘The Chosen’ Season 5 Release Date Info

When Can You Watch ‘The Chosen: Last Supper’ on Streaming Platforms? Details on Season 5 Release Date of ‘The Chosen’

Exciting news for fans of The Chosen: Last Supper – the three…
Hegseth staffers learn their fate after being suspended amid Signal scandal probe

Outcome of suspensions of Hegseth staffers revealed following Signal scandal investigation

The three key staff members working for Defense Secretary Pete Hegseth who…
Jenna Bush Hager Looks Back On Setting Lenny Kravitz Up With Hoda Kotb: “She, Like Every Other Woman In The World, Finds Him Irresistible”

Jenna Bush Hager Reflects on Introducing Lenny Kravitz to Hoda Kotb: “She, like All Women, Can’t Resist Him”

Jenna Bush Hager is known for her matchmaking efforts, particularly involving her…
Husband dies after hatchet-wielding maniac attacks couple in broad daylight at bus stop

Man killed by attacker with hatchet at bus stop in daylight

A Tucson man’s life was tragically cut short after a hatchet-wielding maniac…
What is 764 group? Chicago FBI warns violent online network is targeting minors, activity increasing sharply

“Unveiling the 764 Group: FBI Alerted to Surge in Online Violence Against Minors in Chicago”

CHICAGO (WLS) — The FBI has revealed that the group known as…
Trump tears into 'fool' Democrat Chris Van Hollen 'begging for attention' with El Salvador prison stunt

Trump criticizes Democrat Chris Van Hollen as a ‘fool’ seeking attention with El Salvador prison act

President Donald Trump criticized Chris Van Hollen for visiting El Salvador to…
Nintendo Switch 2 news: Nintendo maintains Switch 2 price amid Trump tariff turmoil, sets new pre-order date

New details about Nintendo Switch 2: Nintendo keeps Switch 2 price unchanged during Trump trade uncertainty and announces a new pre-order start date.

Nintendo has set a new pre-order date for the Switch 2 after…
Ryan Coogler’s ‘Sinners’ Belongs to the Tradition of Vampire-Siege Movies

Ryan Coogler’s Film ‘Sinners’ is a Part of the Vampire-Invasion Movie Genre

Ryan Coogler’s latest film Sinners takes place in 1932, a time when…
Hostage Keith Siegel released by Hamas on mission to lobby Trump, Israel to reach deal to free remaining hostages

Keith Siegel Released by Hamas in Effort to Secure Freedom for Remaining Hostages

WASHINGTON — Finally liberated from captivity, Keith Siegel is anything but free.…
11 Easter Movies on Netflix in 2025 For Kids and For Adults

Top 11 Easter Movies on Netflix for Kids and Adults in 2025

After church, Easter egg hunts, and plenty of Peeps, what is there…
Hugh Jackman takes shock swipe at Deadpool & Wolverine costar Ryan Reynolds

Hugh Jackman surprises by criticizing Ryan Reynolds, his costar in Deadpool and Wolverine films

Hugh Jackman surprised fans when he unloaded on his longtime frenemy Ryan…
5 alleged Tren de Aragua gang members charged in retail thefts, including 1 seen sobbing in police interview

5 supposed members of Tren de Aragua gang accused of shoplifting, with 1 caught crying during questioning by police

A group of individuals believed to be part of the Venezuelan gang…