cbcvebase.
CVE-2025-31277
published 2025-07-30

CVE-2025-31277: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS…

PriorityP185high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-04-03
Exploited in the wild
EPSS
1.48%
71.3th percentile
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
appleios_18.6_and_ipados
appleios_and_ipados< 18.618.6
appleipados< 18.618.6
appleiphone_os< 18.618.6
applemacos< 15.615.6
applemacos>= 15.0 < 15.615.6
applemacos_sequoia
applesafari< 18.618.6
applesafari
appletvos< 18.618.6
appletvos
applevisionos< 2.62.6
applevisionos
applewatchos< 11.611.6
applewatchos
debianwebkit2gtk< webkit2gtk 2.50.1-1~deb12u1 (bookworm)webkit2gtk 2.50.1-1~deb12u1 (bookworm)
debianwpewebkit< webkit2gtk 2.50.1-1~deb12u1 (bookworm)webkit2gtk 2.50.1-1~deb12u1 (bookworm)
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux_aus
redhatenterprise_linux_aus
redhatenterprise_linux_aus
redhatenterprise_linux_els

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2025-31277 is part of the DarkSword iOS exploit kit, which drops three malware families: GhostBlade (JavaScript infostealer), GhostKnife (backdoor), and GhostSaber (JavaScript code execution/data theft)
  • DarkSword exploit kit is delivered via watering-hole attacks targeting iPhone users visiting compromised websites in sectors including e-commerce, industrial equipment, and local services organizations (observed on Ukrainian websites)
  • DarkSword wipes temporary files and exits after data theft — look for short-lived processes and absence of forensic artifacts on iOS devices as an evasion indicator
  • CVE-2025-31277 is attributed to threat actors UNC6748 (customer of Turkish surveillance vendor PARS Defense) and UNC6353 (suspected Russian espionage group); prioritize monitoring of these TTPs
  • CVE-2025-31277 is exploited as part of a 6-vulnerability chain in the DarkSword iOS exploit kit alongside CVE-2025-43510 and CVE-2025-43520; treat all three as co-exploited in the same attack chain
  • DarkSword infrastructure was discovered by Lookout while investigating the Coruna iOS exploit kit — shared infrastructure between DarkSword and Coruna may provide pivoting opportunities for detection
  • ·CVE-2025-31277 is a WebKit buffer overflow (memory corruption) triggered by processing maliciously crafted web content; exploitation occurs passively via browser rendering with no user interaction beyond visiting a compromised page
  • ·The vulnerability affects a wide Apple product surface: Safari 18.6, iOS 18.6, iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, and watchOS 11.6 — all must be patched; CISA remediation deadline is 2026-04-03 for FCEB agencies

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.