CVE-2025-31277
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, watchOS 11.6, visionOS 2.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6. Processing maliciously crafted web content may lead to memory corruption.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS probability
- 1.53%
- CISA KEV
- Known exploited vulnerability
- Published
- 2025-07-29
- Last modified
- 2026-09-01
Affected products
- Apple Safari
- Apple macOS
- Apple tvOS
- Apple visionOS
- Apple watchOS
- Apple iOS and iPadOS
- Apple Safari
- Apple iOS and iPadOS