Home

Description

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.

PUBLISHED Reserved 2025-03-27 | Published 2025-07-29 | Updated 2026-04-02 | Assigner apple

CISA Known Exploited Vulnerability

Date added 2026-03-20 | Due date 2026-04-03

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Problem types

Processing maliciously crafted web content may lead to memory corruption

Product status

Any version before 18.6
affected

Any version before 18.6
affected

Any version before 15.6
affected

Any version before 18.6
affected

Any version before 2.6
affected

Any version before 11.6
affected

References

cloud.google.com/...ntelligence/darksword-ios-exploit-chain/ third-party-advisory

www.cisa.gov/...erabilities-catalog?field_cve=CVE-2025-31277 government-resource

seclists.org/fulldisclosure/2025/Aug/0

seclists.org/fulldisclosure/2025/Jul/36

seclists.org/fulldisclosure/2025/Jul/32

seclists.org/fulldisclosure/2025/Jul/30

support.apple.com/en-us/124147

support.apple.com/en-us/124149

support.apple.com/en-us/124152

support.apple.com/en-us/124153

support.apple.com/en-us/124154

support.apple.com/en-us/124155

cve.org (CVE-2025-31277)

nvd.nist.gov (CVE-2025-31277)

Download JSON