LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-31277: Apple Multiple Products Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 20, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 3, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-31277 to its Known Exploited Vulnerabilities catalog on Mar 20, 2026, with a federal patch deadline of Apr 3, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory…

This vulnerability is a buffer overflow weakness in multiple Apple products that can be triggered when the software processes maliciously crafted web content. The result is memory corruption that may be used to interfere with normal program behavior. It matters for organizations that rely on Apple devices or Safari because web content is processed routinely during normal browsing and application activity, exposing endpoints to remote attacks through standard network traffic.

How it works

The flaw belongs to the CWE-119 class of buffer overflow weaknesses. During handling of web content, an internal buffer can receive more data than it was allocated to hold.

An attacker supplies content designed to exceed those limits, which can overwrite adjacent memory locations and produce corruption that affects control flow or data structures.

Am I affected? How to find it in your systems

The affected components are Apple Safari and the operating systems iOS, watchOS, visionOS, iPadOS, macOS, and tvOS. These run on Apple hardware and any endpoints that use Safari for web access.

Confirm exact versions and exposure conditions against the vendor advisory, as applicability depends on the specific product and build.

How to remediate

Apply the vendor-supplied update referenced in the official advisory as the primary remediation step.

After patching, review and enforce standard hardening measures for buffer-handling code paths in web-content processors, including input-size validation and memory-safety controls where supported by the platform.

If you can't patch immediately

Follow the mitigations documented in the vendor advisory. Where those are unavailable, apply CISA guidance including BOD 22-01 requirements for cloud services or discontinue use of the affected product.

If your data may have been exposed

Actively exploited vulnerabilities in this class can lead to breaches that expose credentials or internal resources. Organizations can run a free exposure scan of their email domains to check for presence in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApple · Multiple Products
WeaknessCWE-119
Added to CISA KEVMar 20, 2026
Federal patch deadlineApr 3, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities