{"id":"CVE-2025-31277","title":"The issue was addressed with improved memory handling","summary":"The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-119","CWE-120"],"vendor":"apple","product":"safari","affected":["safari < 18.6","ipados < 18.6","iphone_os < 18.6","macos >= 15.0, < 15.6","tvos < 18.6","visionos < 2.6","watchos < 11.6","webkitgtk < 2.50.0","wpe_webkit < 2.50.0","enterprise_linux = 6.0","enterprise_linux = 7.0","enterprise_linux = 8.0","enterprise_linux = 9.0","enterprise_linux_aus = 8.2","enterprise_linux_aus = 8.4","enterprise_linux_aus = 8.6","enterprise_linux_els = 7.0","enterprise_linux_eus = 8.4","enterprise_linux_eus = 8.6","enterprise_linux_eus = 9.4","enterprise_linux_tus = 8.6","enterprise_linux_tus = 8.8","enterprise_linux_update_services_for_sap_solutions = 8.6","enterprise_linux_update_services_for_sap_solutions = 8.8","enterprise_linux_update_services_for_sap_solutions = 9.0","enterprise_linux_update_services_for_sap_solutions = 9.2"],"patched":["safari 18.6","ipados 18.6","iphone_os 18.6","macos 15.6","tvos 18.6","visionos 2.6","watchos 11.6","webkitgtk 2.50.0","wpe_webkit 2.50.0"],"published":"2025-07-30","updated":"2026-09-21","sourceUpdated":"2026-09-21T17:17:25.950","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-31277","references":[{"url":"https://support.apple.com/en-us/124147","label":"product-security@apple.com"},{"url":"https://support.apple.com/en-us/124149","label":"product-security@apple.com"},{"url":"https://support.apple.com/en-us/124152","label":"product-security@apple.com"},{"url":"https://support.apple.com/en-us/124153","label":"product-security@apple.com"},{"url":"https://support.apple.com/en-us/124154","label":"product-security@apple.com"},{"url":"https://support.apple.com/en-us/124155","label":"product-security@apple.com"},{"url":"http://seclists.org/fulldisclosure/2025/Aug/0","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://seclists.org/fulldisclosure/2025/Jul/30","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://seclists.org/fulldisclosure/2025/Jul/32","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://seclists.org/fulldisclosure/2025/Jul/36","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2025:17643","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2025:17741","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2025:17743","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2025:17802","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2025:17807","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2025:18097","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2025:19109","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2025:19157","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2025:19165","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2025:19352","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2025-31277","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2448780","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-31277.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-31277","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","in-the-wild","exploit-available","kev"],"exploited":true,"exploitAvailable":true,"ssvc":{"exploitation":"active","automatable":"no","technicalImpact":"total","timestamp":"2026-03-21T04:00:59.438579Z"},"epss":0.01534,"epssPercentile":0.73693,"kev":true,"kevDateAdded":"2026-03-20","kevDueDate":"2026-04-03","kevRansomware":false,"exploits":{"github":1,"githubRepos":["https://github.com/stationedK-06/DarkSword_analysis"],"checkedAt":"2026-09-23T07:13:35.575Z"},"ingestedAt":"2026-06-30T03:49:03.506Z","slug":"CVE-2025-31277","body":"## Overview\n\nThe issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.\n\n## Affected\n\n- `safari < 18.6`\n- `ipados < 18.6`\n- `iphone_os < 18.6`\n- `macos >= 15.0, < 15.6`\n- `tvos < 18.6`\n- `visionos < 2.6`\n- `watchos < 11.6`\n- `webkitgtk < 2.50.0`\n- `wpe_webkit < 2.50.0`\n- `enterprise_linux = 6.0`\n- `enterprise_linux = 7.0`\n- `enterprise_linux = 8.0`\n- `enterprise_linux = 9.0`\n- `enterprise_linux_aus = 8.2`\n- `enterprise_linux_aus = 8.4`\n- `enterprise_linux_aus = 8.6`\n- `enterprise_linux_els = 7.0`\n- `enterprise_linux_eus = 8.4`\n- `enterprise_linux_eus = 8.6`\n- `enterprise_linux_eus = 9.4`\n- `enterprise_linux_tus = 8.6`\n- `enterprise_linux_tus = 8.8`\n- `enterprise_linux_update_services_for_sap_solutions = 8.6`\n- `enterprise_linux_update_services_for_sap_solutions = 8.8`\n- `enterprise_linux_update_services_for_sap_solutions = 9.0`\n- `enterprise_linux_update_services_for_sap_solutions = 9.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `safari 18.6`\n- `ipados 18.6`\n- `iphone_os 18.6`\n- `macos 15.6`\n- `tvos 18.6`\n- `visionos 2.6`\n- `watchos 11.6`\n- `webkitgtk 2.50.0`\n- `wpe_webkit 2.50.0`","depth":"abyssal","depthScore":74,"depthScoreParts":{"impact":48.4,"likelihood":0.3,"exploitation":25,"ransomware":0},"changes":[{"seq":4807,"id":"CVE-2025-31277","ts":1788887208142,"field":"exploit_available","old":"false","new":"true"},{"seq":3690,"id":"CVE-2025-31277","ts":1788886325156,"field":"exploit_available","old":"true","new":"false"},{"seq":2535,"id":"CVE-2025-31277","ts":1788883006807,"field":"exploit_available","old":"false","new":"true"},{"seq":1564,"id":"CVE-2025-31277","ts":1788882407053,"field":"exploit_available","old":"true","new":"false"},{"seq":678,"id":"CVE-2025-31277","ts":1788881843757,"field":"exploit_available","old":"false","new":"true"}]}