CVE-2025-31277
Il problema è stato affrontato con una migliore gestione della memoria. Questo problema è stato corretto in Safari 18.6, iOS 18.6 e iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. L'elaborazione di contenuti web dannosi appositamente creati può portare a memory corruption.
Sfruttata attivamente
- Nel catalogo CISA delle vulnerabilità sfruttate dal 20 mar 2026
- Le agenzie federali statunitensi devono correggerla entro il 3 apr 2026 (direttiva BOD 22-01)
- Primo attacco osservato 231 giorni dopo la divulgazione
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Fonte: CISA KEV · 8 set 2026 19 apr 2026 20 mar 2026 18 mar 2026 18 mar 2026
Punteggio CVSS8.8 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HTipo di debolezza (CWE)CWE-119, CWE-120
Vendorredhat, apple, webkitgtk, wpewebkit
Prodotti coinvolti
| Vendor | Prodotto | Versioni |
|---|---|---|
| apple | safari | < 18.6 |
| apple | ipados | < 18.6 |
| apple | iphone os | < 18.6 |
| apple | macos | < 15.6 |
| apple | tvos | < 18.6 |
| apple | visionos | < 2.6 |
| apple | watchos | < 11.6 |
| webkitgtk | webkitgtk | < 2.50.0 |
| wpewebkit | wpe webkit | < 2.50.0 |
| redhat | enterprise linux | 6.0 |
| redhat | enterprise linux aus | 8.2 |
| redhat | enterprise linux els | 7.0 |
| redhat | enterprise linux eus | 8.4 |
| redhat | enterprise linux tus | 8.6 |
| redhat | enterprise linux update services for sap solutions | 8.6 |
Articoli correlati
This product uses the NVD API but is not endorsed or certified by the NVD.
La descrizione tecnica è una nostra traduzione del testo originale NVD, in inglese.
