CVE-2025-31277
published 2025-07-30CVE-2025-31277: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS…
PriorityP185high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-04-03
Exploited in the wild
EPSS
1.48%
71.3th percentile
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_18.6_and_ipados | — | — |
| apple | ios_and_ipados | < 18.6 | 18.6 |
| apple | ipados | < 18.6 | 18.6 |
| apple | iphone_os | < 18.6 | 18.6 |
| apple | macos | < 15.6 | 15.6 |
| apple | macos | >= 15.0 < 15.6 | 15.6 |
| apple | macos_sequoia | — | — |
| apple | safari | < 18.6 | 18.6 |
| apple | safari | — | — |
| apple | tvos | < 18.6 | 18.6 |
| apple | tvos | — | — |
| apple | visionos | < 2.6 | 2.6 |
| apple | visionos | — | — |
| apple | watchos | < 11.6 | 11.6 |
| apple | watchos | — | — |
| debian | webkit2gtk | < webkit2gtk 2.50.1-1~deb12u1 (bookworm) | webkit2gtk 2.50.1-1~deb12u1 (bookworm) |
| debian | wpewebkit | < webkit2gtk 2.50.1-1~deb12u1 (bookworm) | webkit2gtk 2.50.1-1~deb12u1 (bookworm) |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_aus | — | — |
| redhat | enterprise_linux_aus | — | — |
| redhat | enterprise_linux_aus | — | — |
| redhat | enterprise_linux_els | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2025-31277 is part of the DarkSword iOS exploit kit, which drops three malware families: GhostBlade (JavaScript infostealer), GhostKnife (backdoor), and GhostSaber (JavaScript code execution/data theft) ↗
- →DarkSword exploit kit is delivered via watering-hole attacks targeting iPhone users visiting compromised websites in sectors including e-commerce, industrial equipment, and local services organizations (observed on Ukrainian websites) ↗
- →DarkSword wipes temporary files and exits after data theft — look for short-lived processes and absence of forensic artifacts on iOS devices as an evasion indicator ↗
- →CVE-2025-31277 is attributed to threat actors UNC6748 (customer of Turkish surveillance vendor PARS Defense) and UNC6353 (suspected Russian espionage group); prioritize monitoring of these TTPs ↗
- →CVE-2025-31277 is exploited as part of a 6-vulnerability chain in the DarkSword iOS exploit kit alongside CVE-2025-43510 and CVE-2025-43520; treat all three as co-exploited in the same attack chain ↗
- →DarkSword infrastructure was discovered by Lookout while investigating the Coruna iOS exploit kit — shared infrastructure between DarkSword and Coruna may provide pivoting opportunities for detection ↗
- ·CVE-2025-31277 is a WebKit buffer overflow (memory corruption) triggered by processing maliciously crafted web content; exploitation occurs passively via browser rendering with no user interaction beyond visiting a compromised page ↗
- ·The vulnerability affects a wide Apple product surface: Safari 18.6, iOS 18.6, iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, and watchOS 11.6 — all must be patched; CISA remediation deadline is 2026-04-03 for FCEB agencies ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Apple Multiple Products Buffer Overflow Vulnerability
cisa·2026-03-20·CVSS 8.8
CVE-2025-31277 [HIGH] CWE-119 Apple Multiple Products Buffer Overflow Vulnerability
Vulnerability: Apple Multiple Products Buffer Overflow Vulnerability
Affected: Apple Multiple Products
Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory corruption.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://support.apple.com/en-us/124147 ; https://support.apple.com/en-us/124149 ; https://support.apple.com/en-us/124152 ; https://support.apple.com/en-us/124153 ; https://support.apple.com/en-us/124155 ; https://nvd.nist.gov/vuln/detail/CVE-2025-31277
Remediation Due Date: 2026-04-03
Red Hat
webkitgtk: Processing maliciously crafted web content may lead to memory corruption
vendor_redhat·2026-03-18·CVSS 8.8
CVE-2025-31277 [HIGH] CWE-120 webkitgtk: Processing maliciously crafted web content may lead to memory corruption
webkitgtk: Processing maliciously crafted web content may lead to memory corruption
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.
A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.
Statement: To exploit this issue, an attacker needs to trick a user into processing or loading malicious web content. Due to this reason, this flaw has been rated with an important severity.
Additionally, this issue can cause memory corruption and the possibility of remote code execution is not discarded.
Mitigation: Do not process or
Apple
CVE-2025-31277: Safari 18.6
vendor_apple·2025-07-30·CVSS 8.8
CVE-2025-31277 [HIGH] CVE-2025-31277: Safari 18.6
Apple Security Update: About the security content of Safari 18.6
Product: Safari
Version: 18.6
CVE: CVE-2025-31277
Component: WebKit
Impact: Processing maliciously crafted web content may lead to memory corruption
Description: The issue was addressed with improved memory handling.
Apple
CVE-2025-31277: watchOS 11.6
vendor_apple·2025-07-29·CVSS 8.8
CVE-2025-31277 [HIGH] CVE-2025-31277: watchOS 11.6
Apple Security Update: About the security content of watchOS 11.6
Product: watchOS
Version: 11.6
CVE: CVE-2025-31277
Component: WebKit
Impact: Processing maliciously crafted web content may lead to memory corruption
Description: The issue was addressed with improved memory handling.
Apple
CVE-2025-31277: visionOS 2.6
vendor_apple·2025-07-29·CVSS 8.8
CVE-2025-31277 [HIGH] CVE-2025-31277: visionOS 2.6
Apple Security Update: About the security content of visionOS 2.6
Product: visionOS
Version: 2.6
CVE: CVE-2025-31277
Component: WebKit
Impact: Processing maliciously crafted web content may lead to memory corruption
Description: The issue was addressed with improved memory handling.
Apple
CVE-2025-31277: iOS 18.6 and iPadOS 18.6
vendor_apple·2025-07-29·CVSS 8.8
CVE-2025-31277 [HIGH] CVE-2025-31277: iOS 18.6 and iPadOS 18.6
Apple Security Update: About the security content of iOS 18.6 and iPadOS 18.6
Product: iOS 18.6 and iPadOS
Version: 18.6
CVE: CVE-2025-31277
Component: WebKit
Impact: Processing maliciously crafted web content may lead to memory corruption
Description: The issue was addressed with improved memory handling.
Apple
CVE-2025-31277: macOS Sequoia 15.6
vendor_apple·2025-07-29·CVSS 8.8
CVE-2025-31277 [HIGH] CVE-2025-31277: macOS Sequoia 15.6
Apple Security Update: About the security content of macOS Sequoia 15.6
Product: macOS Sequoia
Version: 15.6
CVE: CVE-2025-31277
Component: WebKit
Impact: Processing maliciously crafted web content may lead to memory corruption
Description: The issue was addressed with improved memory handling.
Apple
CVE-2025-31277: tvOS 18.6
vendor_apple·2025-07-29·CVSS 8.8
CVE-2025-31277 [HIGH] CVE-2025-31277: tvOS 18.6
Apple Security Update: About the security content of tvOS 18.6
Product: tvOS
Version: 18.6
CVE: CVE-2025-31277
Component: WebKit
Impact: Processing maliciously crafted web content may lead to memory corruption
Description: The issue was addressed with improved memory handling.
Red Hat
kernel: jffs2: check that raw node were preallocated before writing summary
vendor_redhat·2025-07-04·CVSS 5.5
CVE-2025-38194 [MEDIUM] CWE-252 kernel: jffs2: check that raw node were preallocated before writing summary
kernel: jffs2: check that raw node were preallocated before writing summary
In the Linux kernel, the following vulnerability has been resolved:
jffs2: check that raw node were preallocated before writing summary
Syzkaller detected a kernel bug in jffs2_link_node_ref, caused by fault
injection in jffs2_prealloc_raw_node_refs. jffs2_sum_write_sumnode doesn't
check return value of jffs2_prealloc_raw_node_refs and simply lets any
error propagate into jffs2_sum_write_data, which eventually calls
jffs2_link_node_ref in order to link the summary to an expectedly allocated
node.
kernel BUG at fs/jffs2/nodelist.c:592!
invalid opcode: 0000 [#1] PREEMPT SMP KASAN NOPTI
CPU: 1 PID: 31277 Comm: syz-executor.7 Not tainted 6.1.128-syzkaller-00139-ge10f83ca10a1 #0
Hardware name: QEMU Standard PC (i440FX
Debian
CVE-2025-31277: webkit2gtk - The issue was addressed with improved memory handling. This issue is fixed in Sa...
vendor_debian·2025·CVSS 8.8
CVE-2025-31277 [HIGH] CVE-2025-31277: webkit2gtk - The issue was addressed with improved memory handling. This issue is fixed in Sa...
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.
Scope: local
bookworm: resolved (fixed in 2.50.1-1~deb12u1)
bullseye: resolved (fixed in 2.50.0-1)
forky: resolved (fixed in 2.50.0-1)
sid: resolved (fixed in 2.50.0-1)
trixie: resolved (fixed in 2.50.1-1~deb13u1)
GHSA
GHSA-vrfh-8v52-6452: The issue was addressed with improved memory handling
ghsa_unreviewed·2025-07-30
CVE-2025-31277 [HIGH] CWE-119 GHSA-vrfh-8v52-6452: The issue was addressed with improved memory handling
The issue was addressed with improved memory handling. This issue is fixed in watchOS 11.6, visionOS 2.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6. Processing maliciously crafted web content may lead to memory corruption.
OSV
CVE-2025-31277: The issue was addressed with improved memory handling
osv·2025-07-30·CVSS 8.8
CVE-2025-31277 [HIGH] CVE-2025-31277: The issue was addressed with improved memory handling
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, watchOS 11.6, visionOS 2.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6. Processing maliciously crafted web content may lead to memory corruption.
OSV
CVE-2025-31277: The issue was addressed with improved memory handling
osv·2025-07-30·CVSS 8.8
CVE-2025-31277 [HIGH] CVE-2025-31277: The issue was addressed with improved memory handling
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.
VulnCheck
Apple Multiple Products Buffer Overflow Vulnerability
vulncheck·2025·CVSS 8.8
CVE-2025-31277 [HIGH] CWE-119 Apple Multiple Products Buffer Overflow Vulnerability
Apple Multiple Products Buffer Overflow Vulnerability
Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory corruption.
Affected: Apple Multiple Products
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/; https://iverify.io/blog/darksword-ios-exploit-kit-explained; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2026-04-03
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Apple expands iOS 18 updates to more iPhones to block DarkSword attacks
blogs_bleepingcomputer·2026-04-01·CVSS 8.8
CVE-2025-31277 [HIGH] Apple expands iOS 18 updates to more iPhones to block DarkSword attacks
## Apple expands iOS 18 updates to more iPhones to block DarkSword attacks
## Lawrence Abrams
In March, researchers at Lookout, iVerify, and Google Threat Intelligence revealed a new "DarkSword" exploit kit that targeted iPhones running iOS 18.4 through 18.7.
The six vulnerabilities used by the DarkSword exploit kit are tracked as CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
While iOS exploits have typically been used in highly targeted spyware campaigns, this iOS exploit kit was used much more widely, including by Turkish commercial surveillance vendor PARS Defense, a threat actor tracked as UNC6748, and a suspected Russian espionage group tracked as UNC6353.
In these attacks, GTIG observed three separate information-stealing mal
Bleepingcomputer
CISA orders feds to patch DarkSword iOS flaws exploited attacks
blogs_bleepingcomputer·2026-03-23·CVSS 8.8
[HIGH] CISA orders feds to patch DarkSword iOS flaws exploited attacks
## CISA orders feds to patch DarkSword iOS flaws exploited attacks
## Sergiu Gatlan
DarkSword was also linked by security researchers to multiple threat groups, including UNC6748, a customer of Turkish commercial surveillance vendor PARS Defense, and a suspected Russian espionage group tracked as UNC6353.
In these attacks, GTIG observed three separate information-theft malware families dropped on victims' devices: a very aggressive JavaScript infostealer named GhostBlade, the GhostKnife backdoor that can exfiltrate large swaths of data, and the GhostSaber JavaScript that executes code and also steals victims' data.
Of the three, UNC6353 deployed both the DarkSword and Coruna iOS exploit kits in watering-hole attacks targeting iPhone users visiting compromised Ukrainian websites of e-co
Hackernews
CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026
blogs_hackernews·2026-03-21·CVSS 8.8
[HIGH] CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added five security flaws impacting Apple, Craft CMS, and Laravel Livewire to its Known Exploited Vulnerabilities ( KEV ) catalog, urging federal agencies to patch them by April 3, 2026.
The vulnerabilities that have come under exploitation are listed below -
CVE-2025-31277 (CVSS score: 8.8) - A vulnerability in Apple WebKit that could result in memory corruption when processing maliciously crafted web content. (Fixed in July 2025)
CVE-2025-43510 (CVSS score: 7.8) - A
Bleepingcomputer
New DarkSword iOS exploit used in infostealer attack on iPhones
blogs_bleepingcomputer·2026-03-18·CVSS 8.8
CVE-2025-31277 [HIGH] New DarkSword iOS exploit used in infostealer attack on iPhones
## New DarkSword iOS exploit used in infostealer attack on iPhones
## Bill Toulas
iVerify's findings indicate that all flaws (sandbox escape, privilege escalation, remote code execution) exploited in this exploit chain are known or documented, and Apple has already addressed them in the latest iOS releases.
The DarkSword exploit kit uses six vulnerabilities tracked as CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
## DarkSword attacks
In a report today, Google Threat Intelligence Group (GTIG) says that DarkSword has been used since at least November 2025 by several threat actors, who deployed three separate malware families:
GHOSTBLADE, a dataminer in JavaScript that steals a swath of information, including crypto wallet data, syst
Mandiant
The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors
blogs_mandiant·2026-03-18
The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors
## The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors
## Google Threat Intelligence Group
## Google Threat Intelligence
Visibility and context on the threats that matter most.
## Introduction
Google Threat Intelligence Group (GTIG) has identified a new iOS full-chain exploit that leveraged multiple zero-day vulnerabilities to fully compromise devices. Based on toolmarks in recovered payloads, we believe the exploit chain to be called DarkSword. Since at least November 2025, GTIG has observed multiple commercial surveillance vendors and suspected state-sponsored actors utilizing DarkSword in distinct campaigns. These threat actors have deployed the exploit chain against targets in Saudi Arabia, Turkey, Malaysia, and Ukraine.
DarkSword supports iOS vers
https://support.apple.com/en-us/124147https://support.apple.com/en-us/124149https://support.apple.com/en-us/124152https://support.apple.com/en-us/124153https://support.apple.com/en-us/124154https://support.apple.com/en-us/124155http://seclists.org/fulldisclosure/2025/Aug/0http://seclists.org/fulldisclosure/2025/Jul/30http://seclists.org/fulldisclosure/2025/Jul/32http://seclists.org/fulldisclosure/2025/Jul/36https://access.redhat.com/errata/RHSA-2025:17643https://access.redhat.com/errata/RHSA-2025:17741https://access.redhat.com/errata/RHSA-2025:17743https://access.redhat.com/errata/RHSA-2025:17802https://access.redhat.com/errata/RHSA-2025:17807https://access.redhat.com/errata/RHSA-2025:18097https://access.redhat.com/errata/RHSA-2025:19109https://access.redhat.com/errata/RHSA-2025:19157https://access.redhat.com/errata/RHSA-2025:19165https://access.redhat.com/errata/RHSA-2025:19352https://access.redhat.com/security/cve/CVE-2025-31277https://bugzilla.redhat.com/show_bug.cgi?id=2448780https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-31277.jsonhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-31277
2025-07-30
Published
2026-03-20
Added to CISA KEV
Exploited in the wild