Apple Multiple Products Buffer Overflow Vulnerability
High CVSS 8.8 Listed in CISA KEV
Summary
Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory corruption.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- Apple:Multiple Products
- :
- :
- :
Sources
- CISA KEV DATABASE
- NVD DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2025-31277 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- https://support.apple.com/en-us/124147 reference
- https://support.apple.com/en-us/124149 reference
- https://support.apple.com/en-us/124152 reference
- https://support.apple.com/en-us/124153 reference
- https://support.apple.com/en-us/124155 reference
- https://support.apple.com/en-us/124154 Release Notes
- http://seclists.org/fulldisclosure/2025/Aug/0 Mailing List
- http://seclists.org/fulldisclosure/2025/Jul/30 Mailing List
- http://seclists.org/fulldisclosure/2025/Jul/32 Mailing List
- http://seclists.org/fulldisclosure/2025/Jul/36 Mailing List
- https://access.redhat.com/errata/RHSA-2025:17643 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:17741 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:17743 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:17802 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:17807 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:18097 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19109 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19157 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19165 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19352 Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2025-31277 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2448780 Third Party Advisory
- https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/ Technical Description
- https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-31277.json Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-31277 US Government Resource
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV
- nvd_ingest NVD