CVE-2025-31277

Confirmed PUBLISHED

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6,...

Apple · Safari, iOS and iPadOS, macOS, tvOS, visionOS, watchOS
Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
8.8 High EPSS 1.5%

At a Glance

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.

cisa
CVE Published
Jul 29, 2025
Exploitation Reported
Jun 01, 2026
CVSS
8.8 High
EPSS
1.5%
Remote Low complexity Unauthenticated

Affected Versions

Vendor Product Version Status
Red Hat
Red Hat Enterprise Linux 7 Extended Lifecycle Support

webkitgtk4

0:2.50.0-1.el7_9 to < *

Unaffected
Red Hat
Red Hat Enterprise Linux 8

webkit2gtk3

0:2.50.0-1.el8_10 to < *

Unaffected
Red Hat
Red Hat Enterprise Linux 8.2 Advanced Update Support

webkit2gtk3

0:2.50.0-1.el8_2 to < *

Unaffected
Red Hat
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support

webkit2gtk3

0:2.50.0-1.el8_4 to < *

Unaffected
Red Hat
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

webkit2gtk3

0:2.50.0-1.el8_4 to < *

Unaffected
Red Hat
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support

webkit2gtk3

0:2.50.0-1.el8_6 to < *

Unaffected
Red Hat
Red Hat Enterprise Linux 8.6 Telecommunications Update Service

webkit2gtk3

0:2.50.0-1.el8_6 to < *

Unaffected
Red Hat
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions

webkit2gtk3

0:2.50.0-1.el8_6 to < *

Unaffected
Red Hat
Red Hat Enterprise Linux 8.8 Telecommunications Update Service

webkit2gtk3

0:2.50.0-1.el8_8.1 to < *

Unaffected
Red Hat
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions

webkit2gtk3

0:2.50.0-1.el8_8.1 to < *

Unaffected
Red Hat
Red Hat Enterprise Linux 9

webkit2gtk3

0:2.50.1-0.el9_6 to < *

Unaffected
Red Hat
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

webkit2gtk3

0:2.50.0-2.el9_0 to < *

Unaffected
Red Hat
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

webkit2gtk3

0:2.50.0-2.el9_2 to < *

Unaffected
Red Hat
Red Hat Enterprise Linux 9.4 Extended Update Support

webkit2gtk3

0:2.50.0-2.el9_4 to < *

Unaffected
Red Hat
Red Hat Enterprise Linux 7

webkitgtk3

All versions (default: unaffected)

Unaffected
Apple
Safari

0 to < 18.6

Affected
Apple
iOS and iPadOS

0 to < 18.6

Affected
Apple
macOS

0 to < 15.6

Affected
Apple
tvOS

0 to < 18.6

Affected
Apple
visionOS

0 to < 2.6

Affected
Apple
watchOS

0 to < 11.6

Affected

CVE References

Show 1 more reference

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.