CVE-2025-31217

The issue was addressed with improved input validation. This issue is fixed in watchOS 11.5, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.
References
Link Resource
https://support.apple.com/en-us/122404 Release Notes Vendor Advisory
https://support.apple.com/en-us/122405 Release Notes Vendor Advisory
https://support.apple.com/en-us/122716 Release Notes Vendor Advisory
https://support.apple.com/en-us/122719 Release Notes Vendor Advisory
https://support.apple.com/en-us/122720 Release Notes Vendor Advisory
https://support.apple.com/en-us/122721 Release Notes Vendor Advisory
https://support.apple.com/en-us/122722 Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

History

27 May 2025, 21:29

Type Values Removed Values Added
References () https://support.apple.com/en-us/122404 - () https://support.apple.com/en-us/122404 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122405 - () https://support.apple.com/en-us/122405 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122716 - () https://support.apple.com/en-us/122716 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122719 - () https://support.apple.com/en-us/122719 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122720 - () https://support.apple.com/en-us/122720 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122721 - () https://support.apple.com/en-us/122721 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122722 - () https://support.apple.com/en-us/122722 - Release Notes, Vendor Advisory
First Time Apple iphone Os
Apple tvos
Apple watchos
Apple ipados
Apple visionos
Apple macos
Apple safari
Apple
CPE cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*

14 May 2025, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 6.5

13 May 2025, 21:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-20

13 May 2025, 19:35

Type Values Removed Values Added
Summary
  • (es) El problema se solucionó mejorando la validación de entrada. Este problema está corregido en watchOS 11.5, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 y iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5 y Safari 18.5. El procesamiento de contenido web malintencionado puede provocar un bloqueo inesperado de Safari.

12 May 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-12 22:15

Updated : 2025-05-27 21:29


NVD link : CVE-2025-31217

Mitre link : CVE-2025-31217

CVE.ORG link : CVE-2025-31217


JSON object : View

Products Affected

apple

  • iphone_os
  • visionos
  • tvos
  • ipados
  • macos
  • safari
  • watchos
CWE
CWE-20

Improper Input Validation