« List of all CVEs

CVE-2025-31277

Published: 7/29/2025 Last updated: 7/15/2026 Reserved: 3/27/2025

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.

CNA assigner: apple (286789f9-fbc2-4510-9f9a-43facdede74c) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 8.8 High CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Opam packages affected (1)

javascriptcore

Products affected (12)

Product Vendor Version
Safari Apple n/a
iOS and iPadOS Apple n/a
macOS Apple Versions 2.1.9.31 and prior
tvOS Apple n/a
visionOS Apple n/a
watchOS Apple n/a
Safari Apple < iOS 12.2
iOS and iPadOS Apple n/a
macOS Apple < publication
tvOS Apple < publication
visionOS Apple < publication
watchOS Apple < publication

References (50)