CVE-2025-31277HIGH 8.8CISA KEVEPSS p69.5%

CVE-2025-31277Apple Multiple Products Buffer Overflow Vulnerability

Apple / Multiple Products

Description

Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory corruption.

Scoring

CVSS 3.18.8 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS1.43% probability of exploitation · percentile 69.5% · 2026-06-18T12:00:27Z
Published2025-07-30
Last modified2026-04-03

CISA KEV entry

Added to KEV: 2026-03-20

Underlying weaknesses· 1

CWE-119

References

  1. https://support.apple.com/en-us/124147
  2. https://support.apple.com/en-us/124149
  3. https://support.apple.com/en-us/124152
  4. https://support.apple.com/en-us/124153
  5. https://support.apple.com/en-us/124154
  6. https://support.apple.com/en-us/124155
  7. http://seclists.org/fulldisclosure/2025/Aug/0
  8. http://seclists.org/fulldisclosure/2025/Jul/30

1

TypeTargetConfidenceTier
WeaknessImproper Restriction of Operations within the Bounds of a Memory Buffercwe-1190%live

(incoming)1

TypeTargetConfidenceTier
KEVEntryApple Multiple Products Buffer Overflow Vulnerabilitykev-cve-2025-312770%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Apple Multiple Products Classic Buffer Overflow Vulnerability
CVE
Apple Multiple Buffer Overflow Vulnerability
CVE
Apple Multiple Products WebKit Memory Corruption Vulnerability
CVE
Apple Multiple Products Integer Overflow or Wraparound Vulnerability
CVE
Apple Multiple Products Memory Corruption Vulnerability
CVE
CVE-2025-31278
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.