CVE detail
CVE-2025-31277
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
30 source links · newest first
- U.S. CISA adds Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the catalog: CISA added the three […]
newssecurityaffairs.comMar 22, 2026, 2:40 PM Apple warns that outdated iPhones are vulnerable to Coruna and DarkSword exploit kits and urges users to update iOS. Apple has warned that iPhones running outdated iOS versions are at risk from exploit kits like Coruna and DarkSword. These attacks use malicious web content to trigger infection chains that can steal sensitive data. Users are […]
newssecurityaffairs.comMar 20, 2026, 11:22 AM- DarkSword: Researchers uncover another iOS exploit kitHelp Net Security
A powerful iPhone hacking toolkit dubbed “DarkSword” has been used since November 2025 to compromise devices by exploiting zero-day iOS vulnerabilities, Google researchers have shared. iOS vulnerabilities exploited by DarkSword Two weeks ago, Google Threat Intelligence Group (GTIG) and iVerify disclosed the existence of Coruna, a spy-grade iOS exploit kit that has been used in a commercial surveillance operation, by state-linked threat actors engaged in cyber espionage, and cybercriminals. While Coruna contains five full iOS … More →
newswww.helpnetsecurity.comMar 19, 2026, 2:41 PM - DarkSword emerges as powerful iOS exploit tool in global attacksSecurity Affairs
DarkSword, a new iOS exploit kit, is used by multiple actors to steal data in campaigns targeting Saudi Arabia, Turkey, Malaysia, and Ukraine. Lookout Threat Labs discovered a new iOS exploit kit called DarkSword that has been used since late 2025 by multiple threat actors, including surveillance vendors and likely nation-state actors. The toolkit enables […]
newssecurityaffairs.comMar 19, 2026, 2:03 PM Targeting six iOS vulnerabilities and leading to full device compromise, the exploit chain is meant for surveillance.
newswww.securityweek.comMar 18, 2026, 3:30 PMe RCE exploit split across two files, rce_module.js and rce_worker_18.4.js (Figure 7). This exploit primarily leveraged CVE-2025-31277, a memory corruption vulnerability in JavaScriptCore (the JavaScript engine used in WebKit and Apple Safari), and also CVE-2026-20700, a Pointer Authentication Codes (PAC) bypass in dyld . We then identified activity se
vendorcloud.google.comMar 18, 2026, 2:00 PMNo excerpt available.
Mitigationwww.cisa.govJul 30, 2025, 12:15 AM- https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-31277.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comJul 30, 2025, 12:15 AM - https://bugzilla.redhat.com/show_bug.cgi?id=2448780bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comJul 30, 2025, 12:15 AM - https://access.redhat.com/security/cve/CVE-2025-31277access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJul 30, 2025, 12:15 AM - https://access.redhat.com/errata/RHSA-2025:19352access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJul 30, 2025, 12:15 AM - https://access.redhat.com/errata/RHSA-2025:19165access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJul 30, 2025, 12:15 AM - https://access.redhat.com/errata/RHSA-2025:19157access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJul 30, 2025, 12:15 AM - https://access.redhat.com/errata/RHSA-2025:19109access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJul 30, 2025, 12:15 AM - https://access.redhat.com/errata/RHSA-2025:18097access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJul 30, 2025, 12:15 AM - https://access.redhat.com/errata/RHSA-2025:17807access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJul 30, 2025, 12:15 AM - https://access.redhat.com/errata/RHSA-2025:17802access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJul 30, 2025, 12:15 AM - https://access.redhat.com/errata/RHSA-2025:17743access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJul 30, 2025, 12:15 AM - https://access.redhat.com/errata/RHSA-2025:17741access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJul 30, 2025, 12:15 AM - https://access.redhat.com/errata/RHSA-2025:17643access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJul 30, 2025, 12:15 AM - http://seclists.org/fulldisclosure/2025/Jul/36seclists.org
No excerpt available.
Exploitseclists.orgJul 30, 2025, 12:15 AM - http://seclists.org/fulldisclosure/2025/Jul/32seclists.org
No excerpt available.
Exploitseclists.orgJul 30, 2025, 12:15 AM - http://seclists.org/fulldisclosure/2025/Jul/30seclists.org
No excerpt available.
Exploitseclists.orgJul 30, 2025, 12:15 AM - http://seclists.org/fulldisclosure/2025/Aug/0seclists.org
No excerpt available.
Exploitseclists.orgJul 30, 2025, 12:15 AM - https://support.apple.com/en-us/124155support.apple.com
No excerpt available.
Vendor Advisorysupport.apple.comJul 30, 2025, 12:15 AM - https://support.apple.com/en-us/124154support.apple.com
No excerpt available.
Vendor Advisorysupport.apple.comJul 30, 2025, 12:15 AM - https://support.apple.com/en-us/124153support.apple.com
No excerpt available.
Vendor Advisorysupport.apple.comJul 30, 2025, 12:15 AM - https://support.apple.com/en-us/124152support.apple.com
No excerpt available.
Vendor Advisorysupport.apple.comJul 30, 2025, 12:15 AM - https://support.apple.com/en-us/124149support.apple.com
No excerpt available.
Vendor Advisorysupport.apple.comJul 30, 2025, 12:15 AM - https://support.apple.com/en-us/124147support.apple.com
No excerpt available.
Vendor Advisorysupport.apple.comJul 30, 2025, 12:15 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2025-43343CVSS 9.8 · Critical
The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing malicio…
- CVE-2026-20635CVSS 4.3 · Medium
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, vis…
- CVE-2025-43214CVSS 6.5 · Medium
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Pro…
- CVE-2025-43213CVSS 6.5 · Medium
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Pro…
- CVE-2025-31223CVSS 8.0 · High
The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing m…
- CVE-2025-43342CVSS 9.8 · Critical
A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, wat…