CVE-2025-31277 is a high-severity memory corruption vulnerability affecting Apple Safari, iOS, iPadOS, macOS, watchOS, visionOS, and tvOS, stemming from improper memory handling when processing maliciously crafted web content. Rated 8.8 HIGH on CVSS, it allows unauthenticated attackers to achieve high impact on confidentiality, integrity, and availability with low attack complexity, though user interaction is required. This vulnerability is actively exploited in the wild, as confirmed by its inclusion in the CISA KEV catalog and reports of its use in sophisticated exploit chains. While no public exploit code is widely available, its active exploitation and significant community attention necessitate immediate patching to Safari 18.6, watchOS 11.6, visionOS 2.6, iOS 18.6, iPadOS 18.6, macOS Sequoia 15.6, and tvOS 18.6.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 18.6CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
< 18.6CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 18.6CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
>= 15.0, < 15.6CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
< 18.6CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.