CVE-2025-31277

High8.8Published on July 29, 2025

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.

Actively exploited

  • In the CISA exploited-vulnerabilities catalogue since Mar 20, 2026
  • US federal agencies must remediate it by Apr 3, 2026 (BOD 22-01)
  • First attack observed 231 days after disclosure

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Source: CISA KEV · Sep 8, 2026 Apr 19, 2026 Mar 20, 2026 Mar 18, 2026 Mar 18, 2026

CVSS score8.8 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness type (CWE)CWE-119, CWE-120
Vendorsredhat, apple, webkitgtk, wpewebkit

Affected products

VendorsProductVersions
applesafari< 18.6
appleipados< 18.6
appleiphone os< 18.6
applemacos< 15.6
appletvos< 18.6
applevisionos< 2.6
applewatchos< 11.6
webkitgtkwebkitgtk< 2.50.0
wpewebkitwpe webkit< 2.50.0
redhatenterprise linux6.0
redhatenterprise linux aus8.2
redhatenterprise linux els7.0
redhatenterprise linux eus8.4
redhatenterprise linux tus8.6
redhatenterprise linux update services for sap solutions8.6

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database