HIGH

CVE-2025-31277

Apple Safari 2025-07-30 CVSS v3.1
CVSS
8.8
KEV

Description

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.

Summary dbcve.org

Memory corruption vulnerability in WebKit (Apple's browser engine) that can be triggered by processing maliciously crafted web content, potentially allowing arbitrary code execution or other memory-related attacks.

Mitigation

Update all affected Apple products (Safari, iOS, iPadOS, macOS, tvOS, visionOS, watchOS) to version 18.6/15.6 or later. Avoid browsing untrusted websites as a temporary measure until patches are applied.

Weakness (CWE)

CWE-119 Memory Buffer Bounds Error
CWE-120 Classic Buffer Overflow

EPSS Score

1.53%
Probability of exploitation in next 30 days
73.7th percentile

References

https://support.apple.com/en-us/124147 Release Notes, Vendor Advisory https://support.apple.com/en-us/124149 Release Notes, Vendor Advisory https://support.apple.com/en-us/124152 Release Notes, Vendor Advisory https://support.apple.com/en-us/124153 Release Notes, Vendor Advisory https://support.apple.com/en-us/124154 Release Notes, Vendor Advisory https://support.apple.com/en-us/124155 Release Notes, Vendor Advisory http://seclists.org/fulldisclosure/2025/Aug/0 Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2025/Jul/30 Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2025/Jul/32 Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2025/Jul/36 Mailing List, Third Party Advisory https://access.redhat.com/errata/RHSA-2025:17643 Third Party Advisory https://access.redhat.com/errata/RHSA-2025:17741 Third Party Advisory https://access.redhat.com/errata/RHSA-2025:17743 Third Party Advisory https://access.redhat.com/errata/RHSA-2025:17802 Third Party Advisory https://access.redhat.com/errata/RHSA-2025:17807 Third Party Advisory https://access.redhat.com/errata/RHSA-2025:18097 Third Party Advisory https://access.redhat.com/errata/RHSA-2025:19109 Third Party Advisory https://access.redhat.com/errata/RHSA-2025:19157 Third Party Advisory https://access.redhat.com/errata/RHSA-2025:19165 Third Party Advisory https://access.redhat.com/errata/RHSA-2025:19352 Third Party Advisory https://access.redhat.com/security/cve/CVE-2025-31277 Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=2448780 Third Party Advisory https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/ Technical Description https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-31277.json Third Party Advisory https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-31277 US Government Resource
View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE