Reference page — cumulative record through Wednesday, October 7, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2025-31277
Apple Multiple Products
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N R U H H H 8.8 .0160 75.0 YES
AFFECTED
Product Versions Fixed
Safari unspecified —
iOS and iPadOS unspecified —
macOS unspecified —
tvOS unspecified —
visionOS unspecified —
watchOS unspecified —
TIMELINE
Mar 27 Reserved by apple
Jul 29 Published (CNA: apple)
Mar 20 Added to CISA KEV, remediation due 2026-04-03
Description
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| March 27, 2025 | Reserved | Reserved by apple |
| July 29, 2025 | Published | Published (CNA: apple) |
| March 20, 2026 | KEV ADDED | Added to CISA KEV, remediation due 2026-04-03 |
Affected
Affected products and packages — 6 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Apple | Safari | — | — | — |
| Apple | iOS and iPadOS | — | — | — |
| Apple | macOS | — | — | — |
| Apple | tvOS | — | — | — |
| Apple | visionOS | — | — | — |
| Apple | watchOS | — | — | — |
References (25)
- http://seclists.org/fulldisclosure/2025/Aug/0 [Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2025/Jul/30 [Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2025/Jul/32 [Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2025/Jul/36 [Mailing List, Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:17643 [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:17741 [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:17743 [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:17802 [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:17807 [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:18097 [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:19109 [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:19157 [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:19165 [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2025:19352 [Third Party Advisory]
- https://access.redhat.com/security/cve/CVE-2025-31277 [Third Party Advisory]
- https://bugzilla.redhat.com/show_bug.cgi?id=2448780 [Third Party Advisory]
- https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/ [Technical Description]
- https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-31277.json [Third Party Advisory]
- https://support.apple.com/en-us/124147 [Release Notes, Vendor Advisory]
- https://support.apple.com/en-us/124149 [Release Notes, Vendor Advisory]
- https://support.apple.com/en-us/124152 [Release Notes, Vendor Advisory]
- https://support.apple.com/en-us/124153 [Release Notes, Vendor Advisory]
- https://support.apple.com/en-us/124154 [Release Notes, Vendor Advisory]
- https://support.apple.com/en-us/124155 [Release Notes, Vendor Advisory]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-31277 [US Government Resource]
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-31277 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, October 7, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.