CVE-2025-31204
Description
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to memory corruption.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Processing maliciously crafted web content via Safari or WebKit could lead to memory corruption, patched in Apple's May 2025 updates.
CVE-2025-31204 is a memory corruption vulnerability in Apple's WebKit engine that arises when processing maliciously crafted web content. The root cause is improper memory handling during web content parsing, which can be triggered by visiting a specially crafted website [1][2][3][4].
Exploitation
Exploitation requires no authentication beyond normal browser access; a victim need only load a malicious webpage in Safari or any app using WebKit. The attacker may deliver the content via a compromised site, phishing link, or ad injection. No special network position is required, making the attack surface broad.
Impact
Successful exploitation could allow an attacker to corrupt memory, potentially leading to arbitrary code execution, unexpected app termination, or disclosure of sensitive information. The vulnerability is rated High with a CVSS v3 score of 8.8, indicating significant impact on confidentiality, integrity, and availability.
Mitigation
Apple has addressed the issue in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, and watchOS 11.5. Users are strongly advised to update affected devices immediately [1][2][3][4]. No workarounds are available, and the vulnerability is not known to be exploited in the wild as of the patch release.
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
7Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
12- support.apple.com/en-us/122404nvdRelease NotesVendor Advisory
- support.apple.com/en-us/122716nvdRelease NotesVendor Advisory
- support.apple.com/en-us/122719nvdRelease NotesVendor Advisory
- support.apple.com/en-us/122720nvdRelease NotesVendor Advisory
- support.apple.com/en-us/122721nvdRelease NotesVendor Advisory
- support.apple.com/en-us/122722nvdRelease NotesVendor Advisory
- seclists.org/fulldisclosure/2025/May/10nvd
- seclists.org/fulldisclosure/2025/May/12nvd
- seclists.org/fulldisclosure/2025/May/13nvd
- seclists.org/fulldisclosure/2025/May/5nvd
- seclists.org/fulldisclosure/2025/May/7nvd
- lists.debian.org/debian-lts-announce/2025/06/msg00016.htmlnvd
News mentions
0No linked articles in our index yet.