CVE

CVE-2025-31277

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, watchOS 11.6, visionOS 2.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6. Processing maliciously crafted web content may lead to memory corruption.

Exploitation IoCs 15

Domain cloudfareintcdn[.]com
Domain funnull-hosted
Package chilltvcms/theme-legend
Package haiau009/kkphim-legend
Package haiau009/kkphim-motchill
Package ophimcms/theme-dy
Package ophimcms/theme-motchill
Package ophimcms/theme-pcc
Package ophimcms/theme-rrdyw
Package vsmov/theme-dy
Package vsmov/theme-motchill
Package vsmov/theme-rrdyw
Package vsmov/theme-vsmov
Package vsphim/theme-heovl
Package vsphim/theme-thempho

MITRE ATT&CK TTPs 6

Source Articles