CVE-2025-31277: Apple Multiple Products Buffer Overflow Vulnerability
Accessibility. A logic issue was addressed with improved checks.
Other sources
Accessibility. The issue was addressed by adding additional logic.
— Apple
Admin Framework. A path handling issue was addressed with improved validation.
— Apple
afclip. The issue was addressed with improved memory handling.
— Apple
AMD. A race condition was addressed with improved state handling.
— Apple
Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory corruption.
— CISA
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.6 - Upgrade
Upgrade
Apple Safarito a version that resolves this vulnerability.Fixed in 18.6 - Upgrade
Upgrade
Apple iOSto a version that resolves this vulnerability.Fixed in 18.6 - Upgrade
Upgrade
Apple iPadOSto a version that resolves this vulnerability.Fixed in 18.6 - Upgrade
Upgrade
Apple macOS Sequoiato a version that resolves this vulnerability.Fixed in 15.6 - Upgrade
Upgrade
Apple tvOSto a version that resolves this vulnerability.Fixed in 18.6 - Upgrade
Upgrade
Apple visionOSto a version that resolves this vulnerability.Fixed in 2.6 - Upgrade
Upgrade
Apple watchOSto a version that resolves this vulnerability.Fixed in 11.6 - Configuration
This issue was addressed by resolving it without loading remote images.
Safari Remote images loading = disabled - Compensating control
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-43186
- CVE-2025-43223
- CVE-2025-43277
- CVE-2025-43210
- CVE-2025-43230
- CVE-2025-43209
- CVE-2025-43226
- CVE-2025-43282
- CVE-2025-7425
- CVE-2025-7424
- CVE-2025-43234
- CVE-2025-43224
- CVE-2025-43221
- CVE-2025-31281
- CVE-2025-6965
- CVE-2025-43227
- CVE-2025-31278
- CVE-2025-31277
- CVE-2025-31273
- CVE-2025-43214
- CVE-2025-43213
- CVE-2025-43212
- CVE-2025-43211
- CVE-2025-43265
- CVE-2025-43216
- CVE-2025-6558
- CVE-2025-31229
- CVE-2025-43217
- CVE-2025-43202
- CVE-2025-31276
- CVE-2025-43280
- CVE-2025-43228
- CVE-2025-43191
- CVE-2025-43244
- CVE-2025-31243
- CVE-2025-43253
- CVE-2025-43249
- CVE-2025-43248
- CVE-2025-43245
- CVE-2025-43281
- CVE-2025-43257
- CVE-2025-43222
- CVE-2025-43220
- CVE-2025-43273
- CVE-2025-43195
- CVE-2025-43199
- CVE-2025-43313
- CVE-2025-43267
- CVE-2025-43187
- CVE-2025-43188
- CVE-2025-43198
- CVE-2025-43254
- CVE-2025-43261
- CVE-2025-31279
- CVE-2025-43255
- CVE-2025-43284
- CVE-2025-43276
- CVE-2025-43268
- CVE-2025-43196
- CVE-2025-43192
- CVE-2025-31275
- CVE-2025-43264
- CVE-2025-43219
- CVE-2025-31280
- CVE-2025-43218
- CVE-2025-43215
- CVE-2025-43275
- CVE-2025-43225
- CVE-2025-43270
- CVE-2025-43266
- CVE-2025-43260
- CVE-2025-43247
- CVE-2025-43194
- CVE-2025-43232
- CVE-2025-43236
- CVE-2025-43235
- CVE-2025-43274
- CVE-2025-24188
- CVE-2025-43241
- CVE-2025-43233
- CVE-2025-43193
- CVE-2025-43250
- CVE-2025-43197
- CVE-2025-43239
- CVE-2025-43243
- CVE-2025-43246
- CVE-2025-43256
- CVE-2025-43206
- CVE-2025-43251
- CVE-2025-43185
- CVE-2025-43189
- CVE-2025-43237
- CVE-2025-43229
- CVE-2025-43240
- CVE-2025-43259
- CVE-2025-43238
- CVE-2025-43252
Frequently Asked Questions
What is the severity of CVE-2025-31277?
CVE-2025-31277 is rated as a moderate severity vulnerability.
How do I fix CVE-2025-31277?
To fix CVE-2025-31277, please update your Apple software to the latest version provided in the advisory for your affected product.
Which Apple products are affected by CVE-2025-31277?
CVE-2025-31277 affects various Apple products including watchOS, macOS Sequoia, iOS, iPadOS, tvOS, visionOS, and Safari.
What types of issues are addressed in CVE-2025-31277?
CVE-2025-31277 addresses logic issues, path handling, and memory handling vulnerabilities.
Is there a workaround for CVE-2025-31277?
There are currently no known effective workarounds for CVE-2025-31277 other than updating to the latest versions.