HIGH
CVE-2025-31277
CVSS
8.8
KEV
Description
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.
Summary dbcve.org
Memory corruption vulnerability in WebKit (Apple's browser engine) that can be triggered by processing maliciously crafted web content, potentially allowing arbitrary code execution or other memory-related attacks.
Mitigation
Update all affected Apple products (Safari, iOS, iPadOS, macOS, tvOS, visionOS, watchOS) to version 18.6/15.6 or later. Avoid browsing untrusted websites as a temporary measure until patches are applied.
Weakness (CWE)
CWE-119
Memory Buffer Bounds Error
CWE-120
Classic Buffer Overflow
EPSS Score
1.53%
Probability of exploitation in next 30 days
73.7th percentile
References
https://support.apple.com/en-us/124147
Release Notes, Vendor Advisory
https://support.apple.com/en-us/124149
Release Notes, Vendor Advisory
https://support.apple.com/en-us/124152
Release Notes, Vendor Advisory
https://support.apple.com/en-us/124153
Release Notes, Vendor Advisory
https://support.apple.com/en-us/124154
Release Notes, Vendor Advisory
https://support.apple.com/en-us/124155
Release Notes, Vendor Advisory
http://seclists.org/fulldisclosure/2025/Aug/0
Mailing List, Third Party Advisory
http://seclists.org/fulldisclosure/2025/Jul/30
Mailing List, Third Party Advisory
http://seclists.org/fulldisclosure/2025/Jul/32
Mailing List, Third Party Advisory
http://seclists.org/fulldisclosure/2025/Jul/36
Mailing List, Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:17643
Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:17741
Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:17743
Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:17802
Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:17807
Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:18097
Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:19109
Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:19157
Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:19165
Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:19352
Third Party Advisory
https://access.redhat.com/security/cve/CVE-2025-31277
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2448780
Third Party Advisory
https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/
Technical Description
https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-31277.json
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-31277
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.