CVE-2025-31277
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.
CVSS score8.8 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HWeakness type (CWE)CWE-119, CWE-120
Vendorsredhat, apple, webkitgtk, wpewebkit
Affected products
| Vendors | Prodotto | Versioni |
|---|---|---|
| apple | safari | < 18.6 |
| apple | ipados | < 18.6 |
| apple | iphone os | < 18.6 |
| apple | macos | < 15.6 |
| apple | tvos | < 18.6 |
| apple | visionos | < 2.6 |
| apple | watchos | < 11.6 |
| webkitgtk | webkitgtk | < 2.50.0 |
| wpewebkit | wpe webkit | < 2.50.0 |
| redhat | enterprise linux | 6.0 |
| redhat | enterprise linux aus | 8.2 |
| redhat | enterprise linux els | 7.0 |
| redhat | enterprise linux eus | 8.4 |
| redhat | enterprise linux tus | 8.6 |
| redhat | enterprise linux update services for sap solutions | 8.6 |
Related articles
This product uses the NVD API but is not endorsed or certified by the NVD.
