CVE-2025-31277
Das Problem wurde durch eine verbesserte Speicherverwaltung behoben. Dieses Problem wurde in Safari 18.6, iOS 18.6 und iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6 behoben. Die Verarbeitung böswillig erstellter Webinhalte kann zu einer Speicherbeschädigung führen.
Aktiv ausgenutzt
- Seit dem 20. März 2026 im CISA-Katalog ausgenutzter Schwachstellen
- US-Bundesbehörden müssen sie bis zum 3. Apr. 2026 beheben (BOD 22-01)
- Erster Angriff 231 Tage nach der Veröffentlichung beobachtet
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Quelle: CISA KEV · 8. Sept. 2026 19. Apr. 2026 20. März 2026 18. März 2026 18. März 2026
CVSS-Score8.8 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HSchwachstellentyp (CWE)CWE-119, CWE-120
Herstellerredhat, apple, webkitgtk, wpewebkit
Betroffene Produkte
| Hersteller | Produkt | Versionen |
|---|---|---|
| apple | safari | < 18.6 |
| apple | ipados | < 18.6 |
| apple | iphone os | < 18.6 |
| apple | macos | < 15.6 |
| apple | tvos | < 18.6 |
| apple | visionos | < 2.6 |
| apple | watchos | < 11.6 |
| webkitgtk | webkitgtk | < 2.50.0 |
| wpewebkit | wpe webkit | < 2.50.0 |
| redhat | enterprise linux | 6.0 |
| redhat | enterprise linux aus | 8.2 |
| redhat | enterprise linux els | 7.0 |
| redhat | enterprise linux eus | 8.4 |
| redhat | enterprise linux tus | 8.6 |
| redhat | enterprise linux update services for sap solutions | 8.6 |
Verwandte Artikel
This product uses the NVD API but is not endorsed or certified by the NVD.
Die technische Beschreibung ist unsere Übersetzung des englischen NVD-Originaltexts.
