CVE-2025-31277
Apple Multiple Products Buffer Overflow Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 April 2026). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 1.53% probability · 73th percentile
- CISA KEV
- Listed 20 March 2026 · due 3 April 2026
- Weakness
- CWE-119, CWE-120
- Affected
- apple/safari · apple/ipados · apple/iphone os · apple/macos · apple/tvos · apple/visionos · apple/watchos · webkitgtk/webkitgtk · wpewebkit/wpe webkit · redhat/enterprise linux · redhat/enterprise linux aus · redhat/enterprise linux els · redhat/enterprise linux eus · redhat/enterprise linux tus · redhat/enterprise linux update services for sap solutions
- Source
- product-security@apple.com
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://support.apple.com/en-us/124147 ; https://support.apple.com/en-us/124149 ; https://support.apple.com/en-us/124152 ; https://support.apple.com/en-us/124153 ; https://support.apple.com/en-us/124155 ; https://nvd.nist.gov/vuln/detail/CVE-2025-31277
References
- https://support.apple.com/en-us/124147Release Notes, Vendor Advisory
- https://support.apple.com/en-us/124149Release Notes, Vendor Advisory
- https://support.apple.com/en-us/124152Release Notes, Vendor Advisory
- https://support.apple.com/en-us/124153Release Notes, Vendor Advisory
- https://support.apple.com/en-us/124154Release Notes, Vendor Advisory
- https://support.apple.com/en-us/124155Release Notes, Vendor Advisory
- http://seclists.org/fulldisclosure/2025/Aug/0Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2025/Jul/30Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2025/Jul/32Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2025/Jul/36Mailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:17643Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:17741Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:17743Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:17802Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:17807Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:18097Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19109Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19157Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19165Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19352Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2025-31277Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2448780Third Party Advisory
- https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/Technical Description
- https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-31277.jsonThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-31277US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.