Vulnerability intelligence
CVE-2025-31277
Apple Multiple Products Buffer Overflow Vulnerability
Apple Multiple Products
Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory corruption.
CVSS Score
—
Unrated
EPSS — Exploit Probability
1.5%
Riskier than 72% of all CVEs · checked 2026-09-04
Exploitation
Confirmed in the wild
KEV since 2026-03-20
Remediation
Unconfirmed
Federal deadline 2026-04-03
CISA required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Deadline for federal agencies: 2026-04-03.
9 articles across 6 outlets · first covered Mar 18, 2026 · latest Mar 22, 2026
Coverage timeline
-
U.S. CISA adds Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities catalogsecurityaffairs.com · Mar 22, 2026
-
CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026thehackernews.com · Mar 21, 2026
-
CISA Adds Five Known Exploited Vulnerabilities to Catalogwww.cisa.gov · Mar 20, 2026
-
CISA Adds CVE-2025-31277 to Known Exploited Vulnerabilities Cataloguewww.cisa.gov · Mar 20, 2026
-
CISA Adds CVE-2025-31277 to Known Exploited Vulnerabilities Cataloguecisa.gov · Mar 20, 2026
-
DarkSword emerges as powerful iOS exploit tool in global attackssecurityaffairs.com · Mar 19, 2026
-
DarkSword iOS Exploit Kit Uses 6 Flaws, 3 Zero-Days for Full Device Takeoverthehackernews.com · Mar 19, 2026
-
DarkSword: iPhone Exploit Kit Serves Spies & Thieves Alikewww.darkreading.com · Mar 18, 2026
-
‘DarkSword’ iOS Exploit Kit Used by State-Sponsored Hackers, Spyware Vendorswww.securityweek.com · Mar 18, 2026