CVE-2025-31277
Apple Safari, Apple iOS and iPadOS, Apple macOS
Published 30 Jul 2025 · updated 21 Sept 2026 · Analyzed
8.8 High · CVSS 3.1, CISA ADP
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 20 Mar 2026, with a remediation deadline of 3 Apr 2026 for US federal agencies.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Description
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.
References
- support.apple.com/en-us/124147 · Release Notes, Vendor Advisory
- support.apple.com/en-us/124149 · Release Notes, Vendor Advisory
- support.apple.com/en-us/124152 · Release Notes, Vendor Advisory
- support.apple.com/en-us/124153 · Release Notes, Vendor Advisory
- support.apple.com/en-us/124154 · Release Notes, Vendor Advisory
- support.apple.com/en-us/124155 · Release Notes, Vendor Advisory
- seclists.org/fulldisclosure/2025/Aug/0 · Mailing List, Third Party Advisory
- seclists.org/fulldisclosure/2025/Jul/30 · Mailing List, Third Party Advisory
- seclists.org/fulldisclosure/2025/Jul/32 · Mailing List, Third Party Advisory
- seclists.org/fulldisclosure/2025/Jul/36 · Mailing List, Third Party Advisory
- access.redhat.com/errata/RHSA-2025:17643 · Third Party Advisory
- access.redhat.com/errata/RHSA-2025:17741 · Third Party Advisory
- access.redhat.com/errata/RHSA-2025:17743 · Third Party Advisory
- access.redhat.com/errata/RHSA-2025:17802 · Third Party Advisory
- access.redhat.com/errata/RHSA-2025:17807 · Third Party Advisory
- access.redhat.com/errata/RHSA-2025:18097 · Third Party Advisory
- access.redhat.com/errata/RHSA-2025:19109 · Third Party Advisory
- access.redhat.com/errata/RHSA-2025:19157 · Third Party Advisory
- access.redhat.com/errata/RHSA-2025:19165 · Third Party Advisory
- access.redhat.com/errata/RHSA-2025:19352 · Third Party Advisory
- access.redhat.com/security/cve/CVE-2025-31277 · Third Party Advisory
- bugzilla.redhat.com/show_bug.cgi?id=2448780 · Third Party Advisory
- cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/ · Technical Description
- security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-31277.json · Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-31277 · US Government Resource