CVE-2025-31277: Apple Multiple Products Buffer Overflow Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2026-03-20. EPSS: 1.6% chance of exploitation in the next 30 days.

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.

Affected products

  • Apple iPadOS: before 18.6 (fixed in 18.6)
  • Apple iPhone OS: before 18.6 (fixed in 18.6)
  • Apple macOS: from 15.0, before 15.6 (fixed in 15.6)
  • Apple Safari: before 18.6 (fixed in 18.6)
  • Apple tvOS: before 18.6 (fixed in 18.6)
  • Apple visionOS: before 2.6 (fixed in 2.6)
  • Apple watchOS: before 11.6 (fixed in 11.6)
  • Red Hat Enterprise Linux: version 6.0 only; version 7.0 only; version 8.0 only; version 9.0 only
  • Red Hat Enterprise Linux Aus: version 8.2 only; version 8.4 only; version 8.6 only
  • Red Hat Enterprise Linux Els: version 7.0 only
  • Red Hat Enterprise Linux Eus: version 8.4 only; version 8.6 only; version 9.4 only
  • Red Hat Enterprise Linux Tus: version 8.6 only; version 8.8 only
  • Red Hat Enterprise Linux Update Services For SAP Solutions: version 8.6 only; version 8.8 only; version 9.0 only; version 9.2 only
  • WebKitGTK WebKitGTK: before 2.50.0 (fixed in 2.50.0)
  • Wpewebkit Wpe Webkit: before 2.50.0 (fixed in 2.50.0)

Published 2025-07-30. Last modified 2026-09-21.