CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-31277

KEV High · CVSS 8.8

WebKit — Buffer overflow / memory corruption via maliciously crafted web content (CWE-119, CWE-120)

CVSS
8.8
nvd
EPSS
KEV
Listed
2026-03-20
Class
oss containerizable
CWE-119, CWE-120

Description

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.

Search profile — drives PoC discovery

Symbols WebKitmemory corruptionweb content processingbuffer overflowSafariWKWebView
Keywords CVE-2025-31277WebKit memory corruptionSafari 18.6 exploitiOS 18.6 WebKitmacOS Sequoia 15.6 WebKitWebKit buffer overflow PoCmaliciously crafted web content memory corruption
Versions: Safari < 18.6, iOS/iPadOS < 18.6, macOS Sequoia < 15.6, tvOS < 18.6, visionOS < 2.6, watchOS < 11.6

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-06-30T18:30:14.000Z