CVE-2025-31277 KEV
8.8
HIGH · CVSS 3.1 · EPSS 1.6% (pctl 75)
Patch first
On CISA KEV — known exploited in the wild, due 2026-04-03.
Description
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.
Scoring
| CVSS | 8.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 1.63% — more likely to be exploited than 75% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | yes — remediate by 2026-04-03 |
| Public exploit | none known |
| Published | 2025-07-30 |
| Last modified | 2026-09-21 |
CISA KEV
| Name | Apple Multiple Products Buffer Overflow Vulnerability |
|---|---|
| Added | 2026-03-20 |
| Due | 2026-04-03 |
| Vendor / product | Apple / Multiple Products |
| Ransomware use | none reported |
Affected (15)
| Vendor | Product |
|---|---|
| apple | ipados |
| apple | iphone os |
| apple | macos |
| apple | safari |
| apple | tvos |
| apple | visionos |
| apple | watchos |
| redhat | enterprise linux |
| redhat | enterprise linux aus |
| redhat | enterprise linux els |
| redhat | enterprise linux eus |
| redhat | enterprise linux tus |
| redhat | enterprise linux update services for sap solutions |
| webkitgtk | webkitgtk |
| wpewebkit | wpe webkit |
References
- https://support.apple.com/en-us/124147
- https://support.apple.com/en-us/124149
- https://support.apple.com/en-us/124152
- https://support.apple.com/en-us/124153
- https://support.apple.com/en-us/124154
- https://support.apple.com/en-us/124155
- http://seclists.org/fulldisclosure/2025/Aug/0
- http://seclists.org/fulldisclosure/2025/Jul/30
- http://seclists.org/fulldisclosure/2025/Jul/32
- http://seclists.org/fulldisclosure/2025/Jul/36
- https://access.redhat.com/errata/RHSA-2025:17643
- https://access.redhat.com/errata/RHSA-2025:17741
- https://access.redhat.com/errata/RHSA-2025:17743
- https://access.redhat.com/errata/RHSA-2025:17802
- https://access.redhat.com/errata/RHSA-2025:17807
- https://access.redhat.com/errata/RHSA-2025:18097
- https://access.redhat.com/errata/RHSA-2025:19109
- https://access.redhat.com/errata/RHSA-2025:19157
- https://access.redhat.com/errata/RHSA-2025:19165
- https://access.redhat.com/errata/RHSA-2025:19352
→ the Explorer · watch your stack · NVD