PT-2025-31278 · Apple · Visionos+6

·

CVE-2025-31277

·

Published

2025-07-29

·

Updated

2026-09-01

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions WebKitGTK (affected versions not specified) WPE WebKit (affected versions not specified) Safari versions prior to 18.6 iOS versions prior to 18.6 iPadOS versions prior to 18.6 macOS Sequoia versions prior to 15.6 tvOS versions prior to 18.6 visionOS versions prior to 2.6 watchOS versions prior to 11.6
Description Processing maliciously crafted web content can lead to memory corruption due to improper memory handling. This issue manifests as a buffer overflow, which may allow a remote attacker to cause a denial of service. This flaw is confirmed to be under active exploitation in the wild.
Recommendations Update Safari to version 18.6 Update iOS to version 18.6 Update iPadOS to version 18.6 Update macOS Sequoia to version 15.6 Update tvOS to version 18.6 Update visionOS to version 2.6 Update watchOS to version 11.6 At the moment, there is no information about a newer version that contains a fix for this vulnerability for WebKitGTK and WPE WebKit.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06685
CVE-2025-31277
OPENSUSE-SU-2026:20518-1
RHSA-2025:17643
RHSA-2025:17741
RHSA-2025:17743
RHSA-2025:17802
RHSA-2025:17807
RHSA-2025:18097
RHSA-2025:19109
RHSA-2025:19157
RHSA-2025:19165
RHSA-2025:19352
SUSE-SU-2026:1139-1
SUSE-SU-2026:1150-1
SUSE-SU-2026:1364-1
SUSE-SU-2026:21180-1

Affected Products

Apple Macos
Ios
Ipados
Macos Sequoia
Tvos
Visionos
Watchos