VYPR
High severity8.8NVD Advisory· Published Jul 30, 2025· Updated Apr 2, 2026

CVE-2025-31273

CVE-2025-31273

Description

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Memory corruption in WebKit due to improper memory handling could be exploited via crafted web content; fixed in multiple Apple OS updates.

CVE-2025-31273 is a memory corruption vulnerability in WebKit, Apple's browser engine. The root cause is improper memory handling when processing web content, which can lead to memory corruption [1][2][3][4].

An attacker can exploit this vulnerability by convincing a user to view a maliciously crafted webpage. No special privileges are required; the attacker only needs to serve the malicious content. This can be done through email links, advertisements, or compromised websites.

Successful exploitation could lead to arbitrary code execution or a denial of service. Memory corruption vulnerabilities often allow an attacker to execute arbitrary code within the context of the vulnerable process, potentially leading to full system compromise.

Apple has addressed the issue with improved memory handling in Safari 18.6, iOS 18.6, iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, and watchOS 11.6. Users are strongly advised to update their devices to the latest available versions. No workarounds are available.

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

7

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

12

News mentions

0

No linked articles in our index yet.