CVE-2025-31277Active Exploitation(apple / enterprise_linux)

CRITICALCVSS 8.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch apple enterprise_linux systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-04-03. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-119CWE-120

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • enterprise_linux_aus
  • enterprise_linux_els
  • enterprise_linux_eus

Threat summary

  • Active exploitation appears in 27 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 38 mentions across 17 observed days

What's happening

  • Active exploitation reported across 27 signals
  • Exploit tool or code specified in 6 signals
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 20 signals
  • Technical details provided in 24 signals
  • General: 4 classified signals
  • Peaked 13d ago at 5 mentions (2026-03-21); latest day: 1
  • 38 total mentions across 17 days

Affected systems

Products
enterprise_linuxenterprise_linux_ausenterprise_linux_elsenterprise_linux_eusenterprise_linux_tusenterprise_linux_update_services_for_sap_solutionsipadosiphone_osmacossafari

10 versions affected across 15 products

Deep dive

Activity timeline38 mentions / 17d
01345Mentions · 2026-03-18: 3Mentions · 2026-03-19: 2Mentions · 2026-03-20: 4Mentions · 2026-03-21: 5Mentions · 2026-03-22: 1Mentions · 2026-03-23: 5Mentions · 2026-03-24: 1Mentions · 2026-03-25: 2Mentions · 2026-03-27: 2Mentions · 2026-03-28: 5Mentions · 2026-03-29: 1Mentions · 2026-03-30: 1Mentions · 2026-03-31: 1Mentions · 2026-06-28: 1Mentions · 2026-06-30: 1Mentions · 2026-09-01: 2Mentions · 2026-09-21: 1PoC Mentioned / Linked · 2026-03-23: 1PoC Mentioned / Linked · 2026-03-25: 1PoC Mentioned / Linked · 2026-03-27: 1PoC Mentioned / Linked · 2026-03-28: 3Exploit Tool / Code · 2026-03-18: 1Exploit Tool / Code · 2026-03-19: 1Exploit Tool / Code · 2026-03-23: 1Exploit Tool / Code · 2026-03-24: 1Exploit Tool / Code · 2026-03-25: 1Exploit Tool / Code · 2026-03-30: 1Active Exploitation · 2026-03-18: 2Active Exploitation · 2026-03-19: 1Active Exploitation · 2026-03-20: 2Active Exploitation · 2026-03-21: 3Active Exploitation · 2026-03-22: 1Active Exploitation · 2026-03-23: 4Active Exploitation · 2026-03-24: 1Active Exploitation · 2026-03-25: 1Active Exploitation · 2026-03-27: 2Active Exploitation · 2026-03-28: 5Active Exploitation · 2026-03-30: 1Active Exploitation · 2026-03-31: 1Active Exploitation · 2026-06-30: 1Active Exploitation · 2026-09-01: 2Patch / Workaround · 2026-03-18: 3Patch / Workaround · 2026-03-20: 2Patch / Workaround · 2026-03-21: 2Patch / Workaround · 2026-03-23: 2Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-03-28: 5Patch / Workaround · 2026-03-30: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-09-01: 1Patch / Workaround · 2026-09-21: 1Technical Details · 2026-03-18: 1Technical Details · 2026-03-20: 3Technical Details · 2026-03-21: 5Technical Details · 2026-03-23: 4Technical Details · 2026-03-24: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-27: 2Technical Details · 2026-03-28: 3Technical Details · 2026-03-30: 1Technical Details · 2026-06-28: 1Technical Details · 2026-06-30: 1Technical Details · 2026-09-01: 103-1803-1903-2003-2103-2203-2303-2403-2503-2703-2803-2903-3003-3106-2806-3009-0109-21
Signal classification5 categories
Active Exploitation
2257.9%
Patch
718.4%
General
410.5%
Disclosure
37.9%
Exploit
25.3%
Referenced assets30 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-183
Active Exploitation1Patch2
2026-03-192
Exploit1General1
2026-03-204
Active Exploitation2Disclosure1Patch1
2026-03-215
Active Exploitation2Disclosure2Patch1
2026-03-221
Active Exploitation1
2026-03-235
Active Exploitation4General1
2026-03-241
Active Exploitation1
2026-03-252
Active Exploitation1Exploit1
2026-03-272
Active Exploitation2
2026-03-285
Active Exploitation4Patch1
2026-03-291
General1
2026-03-301
Active Exploitation1
2026-03-311
Patch1
2026-06-281
General1
2026-06-301
Active Exploitation1
2026-09-012
Active Exploitation2
2026-09-211
Patch1
Full discourse20 posts
  • YogSotho@YogSoth0
    General

    #DarkSword #iOS #Exploit Chain — Six-Stage Nuclear Exploit Kit Exploit Chain: CVE-2025-31277 → CVE-2026-20700 → CVE-2025-14174 → CVE-2025-43510 → CVE-2025-43520 Target: iOS 18.4 - 18.7 (#Safari/#WebKit) Effect: Full device compromise from one click (watering hole) Privileges: Root / Kernel-level #0days #security #hacking #root #CVE

    Post summary

    The message lists a chain of CVEs targeting iOS Safari/WebKit, claiming a single click could lead to full device compromise, but offers no proof‑of‑concept, exploit code, or patch information.

    113611988516.2K
    1.9K followersView on X
  • Grok@grok
    Active Exploitation

    Update your iPhone to the latest iOS version immediately. It patches the 6 vulnerabilities (including CVE-2025-31277 etc.) used by the DarkSword exploit kit targeting iOS 18.4-18.7. If high-risk, enable Lockdown Mode (Settings > Privacy & Security). Avoid untrusted sites/links in Safari - this spreads via compromised webpages. Stay safe.

    Post summary

    The text highlights that CVE-2025-31277 and related vulnerabilities are actively exploited by the DarkSword exploit kit, urges immediate iOS updates for patching, and recommends enabling Lockdown Mode as a mitigation.

    00041113.6K
    8.5M followersView on X
  • Adam@seoscottsdale
    Active Exploitation

    ⚠️ @thehackernews nailed it. DarkSword = 6-zero-day iOS full chain (CVE-2025-31277 JSCore + CVE-2025-43520 XNU kernel) compromising 221 million+ unpatched devices (iOS 18.4–18.6.2) via zero-click watering-hole sites. Fileless JS, hit-and-run crypto/credential theft, then self-clean. Update to iOS 18.7.6 or 26.3.1 NOW. Can’t? Enable Lockdown Mode immediately. Who’s still on vulnerable iOS? Drop your version below 👇 #DarkSword #iOSSecurity #ZeroDay #Apple

    Post summary

    DarkSword zero-day chain is actively exploiting over 221 million iOS devices via zero-click watering holes, prompting urgent updates or Lockdown Mode.

    02033766
    12.4K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(3/20追加) 🛡️No.1548 CVE-2025-31277 Apple Multiple Products Buffer Overflow Vulnerability ==================================== ✅概要 ・深刻度:重要⚠️ 8.8 (CVSS Base) / CISA-ADP ・種別:バッファ境界の不適切な制限 (CWE-119) ・CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Apple の複数製品において、悪意ある Web コンテンツの処理によりメモリ破損が発生し得る脆弱性。 ✅ChatGPTによる脆弱性評価 ・国内影響度判定:高 ・悪用難易度:中 ✅攻撃前提条件 ・被害者が細工された Web コンテンツを処理すること ・脆弱な Apple 製品を利用していること ✅悪用時影響 ・メモリ破損 ・任意コード実行の可能性 ・端末侵害の初期侵入点化 ✅悪用事例等に関する公開情報 ・PoC/Exploit:確認できず ・ITW:あり(Google Threat Intelligence Group が DarkSword での利用を報告。) ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-31277 https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/ https://support.apple.com/en-us/124147 🛡️No.1549 CVE-2025-43510 Apple Multiple Products Improper Locking Vulnerability ==================================== ✅概要 ・深刻度:重要⚠️ 7.8 (CVSS Base) / NVD ・種別:不適切なロック (CWE-667) ・CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 事前認証されていない攻撃者により、悪意あるアプリを介して、プロセス間で共有されるメモリに予期しない変更を生じさせる恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅攻撃前提条件 ・被害端末上で悪意あるアプリを実行させること ・脆弱な Apple 製品を利用していること ✅悪用時影響 ・共有メモリの不正変更 ・プロセス間干渉 ・後続の権限奪取やチェーン攻撃の踏み台化 ✅悪用事例等に関する公開情報 ・PoC/Exploit:確認できず ・ITW:あり(Google Threat Intelligence Group が、DarkSword の GPU サンドボックス脱出段階で使用したと説明。) ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-43510 https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/ https://support.apple.com/en-us/125632 🛡️No.1550 CVE-2025-43520 Apple Multiple Products Classic Buffer Overflow Vulnerability ==================================== ✅概要 ・深刻度:重要⚠️ 7.1 (CVSS Base) / NVD ・種別:境界外書き込み (CWE-787) / NVD、クラシックバッファオーバーフロー (CWE-120) / CISA-ADP ・CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H 事前認証されていない攻撃者により、悪意あるアプリを介して、予期しないシステム終了やカーネルメモリ書き込みを引き起こされる恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅攻撃前提条件 ・被害端末上で悪意あるアプリを実行させること ・脆弱な Apple 製品を利用していること ✅悪用時影響 ・システム異常終了 ・カーネルメモリ書き込み ・権限昇格や端末掌握の足掛かり ([NVD][6]) ✅悪用事例等に関する公開情報 ・PoC/Exploit:確認できず ・ITW:あり(GTIG が DarkSword の最終段階 `pe_main.js` において、脆弱性を悪用し物理/仮想メモリ でread/write primitive を構築すると説明) ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-43520 https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/ https://support.apple.com/en-us/125633 🛡️No.1551 CVE-2025-32432 Craft CMS Code Injection Vulnerability =================================== ✅概要 ・深刻度:緊急🔥 10.0 (CVSS Base) / NVD ・種別:コード生成の不適切な制御 (CWE-94) / GitHub, Inc. ・CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 事前認証されていない攻撃者により、リモートからコード実行される恐れがあります。Craft CMS において、3.0.0-RC1 以上 3.9.15 未満、4.0.0-RC1 以上 4.14.15 未満、5.0.0-RC1 以上 5.6.17 未満が影響を受けます。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅攻撃前提条件 ・Craft CMS が外部公開されていること ・脆弱バージョンが稼働していること ・攻撃者は認証不要、ユーザー操作不要 ✅悪用時影響 ・未認証でのリモートコード実行 ・Web サーバ侵害 ・情報窃取 ・Web 改ざんや追加マルウェア設置 ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報あり ・ITW:あり(Craft CMS は 2025-04-17 に “exploited in the wild” を示唆する証拠を確認したと公表) ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-32432 https://github.com/craftcms/cms/security/advisories/GHSA-f3gw-9ww9-jmc3 https://craftcms.com/knowledge-base/craft-cms-cve-2025-32432](https://craftcms.com/knowledge-base/craft-cms-cve-2025-32432 🛡️No.1552 CVE-2025-54068 Laravel Livewire Code Injection Vulnerability ==================================== ✅概要 ・深刻度:緊急🔥 9.8 (CVSS Base) / NVD ・種別:コード生成の不適切な制御 (CWE-94) / GitHub, Inc. ・CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Livewire v3.0.0 以上 3.6.4 未満において、特定の component property update の hydration 処理に起因。事前認証されていない攻撃者により、特定条件下でリモートからコード実行される恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅攻撃前提条件 ・Livewire v3 系の脆弱バージョンが公開環境で稼働していること ・対象コンポーネントが特定の方法で mounted / configured されていること ✅悪用時影響 ・未認証でのリモートコマンド実行 ・アプリケーションサーバ侵害 ・情報窃取 ・追加マルウェア設置や横展開 ([NVD][7]) ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報あり ・ITW:あり(ThreatHunter .ai はイラン系脅威アクターから、CVE-2025-54068 向け custom Nuclei template と 9 confirmed targets を報告) ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-54068 https://github.com/livewire/livewire/security/advisories/GHSA-29cq-5w36-x7w3 https://www.threathunter.ai/blog/iranian-threat-actor-tools-techniques-iocs-ioas/ https://www.cisa.gov/news-events/alerts/2026/03/20/cisa-adds-five-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    The post details five CVEs added to CISA’s Exploited Vulnerabilities catalog, providing PoC links, active exploitation evidence from Google and ThreatHunter, and vendor patch references with full technical details.

    030414.0K
    42.8K followersView on X
  • Grok@grok
    Active Exploitation

    DarkSword is a sophisticated iOS exploit chain using multiple zero-days (like CVE-2025-31277, CVE-2025-43529) to fully compromise iPhones via a malicious Safari page—no clicks needed. It was used by state/commercial actors (targeting Ukraine, Saudi Arabia, etc.) for data theft (messages, creds, crypto wallets). A version leaked on GitHub ~3 days ago, so now any script kiddie can deploy it easily on unpatched devices. Hits iOS 18.4–18.7 (not 18.7.3+ or iOS 26.3+). Update now via Settings > General > Software Update. Lockdown Mode helps too.

    Post summary

    DarkSword, an iOS exploit chain targeting CVE‑2025‑31277 and CVE‑2025‑43529, is actively being used by threat actors, has leaked on GitHub, and affects iOS 18.4‑18.7; users should update via Settings > General > Software Update and enable Lockdown Mode.

    000311.5K
    8.5M followersView on X
  • Kuncoro@0xkuncoro
    Patch

    @A_K_Mandhan Two of the WebKit bugs are already patched: CVE-2025-31277 (iOS 18.6) and CVE-2025-43529 (18.7.3 and 26.2). The kernel escape is n-day reuse of the DarkSword chain GTIG published, so anyone still below 18.7.3 stays exposed. Updating past those closes the route.

    Post summary

    The tweet confirms CVE-2025-31277 and CVE-2025-43529 are patched in iOS 18.6, 18.7.3, and 26.2, and explicitly urges updating to those versions to close the exposure route for the kernel escape chain.

    10020656
    155 followersView on X
  • CVERiskPilot@cveriskpilot
    Active Exploitation

    3 Apple CVEs hit the CISA KEV this week — all actively exploited: CVE-2025-31277 (memory corruption) CVE-2025-43510 (DoS) CVE-2025-43520 (buffer overflow) iOS, macOS, watchOS, visionOS affected. Update everything. Today. #Apple #AppSec

    Post summary

    Three Apple CVEs (CVE-2025-31277, CVE-2025-43510, CVE-2025-43520) were recently added to the CISA KEV as actively exploited, affecting iOS, macOS, watchOS, and visionOS; immediate updates are advised.

    00030150
    13 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2020-5902 2 - CVE-2026-33634 3 - CVE-2025-31277 4 - CVE-2026-20643 5 - CVE-2025-53521 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    A tweet simply lists the top 5 trending CVEs without providing any detailed information or actionable insights.

    00011395
    1.7K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows UNC6353 deployed the DarkSword exploit kit to chain iOS vulnerabilities CVE-2025-31277, CVE-2025-43510, and CVE-2025-43520. Attackers escaped sandboxes, escalated privileges, and moved laterally across compromised devices to steal cryptocurrency wallet credentials. #MobileSecurity #ThreatIntel 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/darksword-ios-exploit-kit-2026-unc6353-crypto-theft

    Post summary

    UNC6353 is actively exploiting iOS CVEs 2025‑31277, 43510, and 43520 with the DarkSword exploit kit to escape sandboxes, elevate privileges, and steal crypto wallet credentials.

    01010240
    1.9K followersView on X
  • キタきつね@foxbook
    General

    CISAが既知の悪用された脆弱性5件をカタログに追加 CISA Adds Five Known Exploited Vulnerabilities to Catalog #CISA (Mar 20) CVE-2025-31277 Apple複数製品におけるバッファオーバーフローの脆弱性 CVE-2025-32432 Craft CMS コードインジェクションの脆弱性 CVE-2025-43510 Apple複数製品における不適切なロックの脆弱性 CVE-2025-43520 Apple複数製品におけるクラシックバッファオーバーフローの脆弱性 CVE-2025-54068 Laravel Livewireのコードインジェクション脆弱性 https://www.cisa.gov/news-events/alerts/2026/03/20/cisa-adds-five-known-exploited-vulnerabilities-catalog

    Post summary

    CISA’s announcement adds five previously exploited vulnerabilities to its catalog, detailing their types (buffer overflows, code injection, improper lock) across Apple, Craft CMS, and Laravel Livewire, but offers no PoC, exploit code, or patch information.

    00020256
    4.8K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-3888 2 - CVE-2025-31277 3 - CVE-2025-55182 4 - CVE-2026-20643 5 - CVE-2026-32746 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post presents a ranked list of trending CVEs without providing any PoC, exploit code, active exploitation evidence, patch details, technical specifics, or correctness claims.

    00011199
    1.7K followersView on X
  • The Daily Tech Feed@dailytechonx
    Active Exploitation

    Dangerous new supply chain attack: booby-trapped Composer themes on Vietnamese streaming sites compromise WebKit via CVE-2025-31277 & CVE-2025-43529, with iPhones affected when unpatched. Wallet seed phrases, contacts, messages, everything at risk. Check installed themes, update iOS immediately, audit domains and dependencies, and block known infrastructure. #Security #WebKit #SupplyChainAttack #CryptoTheft #iPhoneSecurity #Malware https://thedailytechfeed.com/iphone-wallet-seeds-at-risk-malicious-website-themes-reveal-threat/

    Post summary

    The post describes a supply‑chain attack using CVE-2025-31277 and CVE-2025-43529 to compromise WebKit on iPhones, with ongoing real‑world exploitation and a call to update iOS as mitigation.

    0000178
    691 followersView on X
  • Adam@seoscottsdale
    Active Exploitation

    🚨 iOS Security 101: Lockdown Mode explained (perfect for DarkSword-level threats) With iOS 26.4 now out, the 6-zero-day DarkSword chain (incl. CVE-2025-31277 + CVE-2025-43520) has been publicly leaked on GitHub. Multiple actors (TA446 etc.) are actively using it. CISA added the CVEs to KEV. Apple is pushing Lock Screen “Critical Software” alerts to vulnerable devices. Not for everyday users — it’s built for high-risk people (journalists, activists, politicians). Normal iOS security handles 99% of threats. 🛡️ When ON, it slashes your device’s attack surface: • Blocks complex web tech in Safari (kills web-based exploits like DarkSword cold) • Most Messages attachments & links disabled • FaceTime incoming calls limited • No new shared Photo albums • No 2G/3G, no auto insecure Wi-Fi • Must unlock to connect accessories/computers • Game Center, Focus, MDM changes blocked Trade-off: Some apps & sites feel broken. Basic calls, texts & SOS still work fine. ✅ Works on iOS 16+, iPadOS 16+, watchOS 10+, macOS Ventura+ How to turn it on (iPhone/iPad): 1. Settings → Privacy & Security 2. Tap Lockdown Mode 3. Turn On & Restart (Your paired Apple Watch auto-enables too) Bottom line: Lockdown Mode stops DarkSword-style Safari attacks cold. With the exploit now public + iOS 26.4 available, high-risk users should enable it TODAY. Everyone else → just update to iOS 26.4 immediately (or 18.7.7 on older hardware). Easy to test & disable anytime. What iOS version are you running? 👇 #iOSSecurity #DarkSword #LockdownMode #CyberSecurity

    Post summary

    The post announces that CVEs from the DarkSword chain have been publicly leaked and are actively exploited, urging users to enable Lockdown Mode or update to the latest iOS as a mitigation.

    10000407
    12.4K followersView on X
  • bigmacd@bigmacd16684
    Active Exploitation

    "DarkSword" exploit chain, live since Nov 2025, linked 6 flaws: JavaScriptCore (CVE-2025-31277, CVE-2025-43529), dyld PAC bypass (CVE-2026-20700), WebContent sandbox escape (CVE-2025-14174). #cybersecurity

    Post summary

    The DarkSword exploit chain has been active since November 2025, targeting multiple CVEs across JavaScriptCore, dyld, and WebContent sandbox escape, with no mention of patches or PoC details.

    100006
    4 followersView on X
  • EdgeDetectOps@EdgeDetectOps
    Disclosure

    🚨 Today CVE: CVE-2025-31277. Curious how quickly this started getting scanned. Apple buffer overflow across the entire ecosystem. Safari, iOS, macOS, watchOS, visionOS, iPadOS, tvOS. When one falls, they all fall.

    Post summary

    The post announces a newly disclosed Apple buffer overflow (CVE-2025-31277) that spans the entire ecosystem, without providing PoC, exploit, or patch details.

    1000012
    13 followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Active Exploitation

    CISAが既知の悪用された脆弱性5件をカタログに追加 https://www.cisa.gov/news-events/alerts/2026/03/20/cisa-adds-five-known-exploited-vulnerabilities-catalog CVE-2025-31277 Apple複数製品におけるバッファオーバーフローの脆弱性 CVE-2025-32432 Craft CMS コードインジェクションの脆弱性

    Post summary

    A CISA alert added five known exploited vulnerabilities—including a buffer overflow in Apple products and a code injection flaw in Craft CMS—to its catalog, confirming ongoing exploitation but offering no PoC, exploit code, or patch details.

    10000148
    46 followersView on X
  • DFIR Radar@DFIR_Radar
    Exploit

    Russian 🇷🇺 UNC6353 deploys "DarkSword" iOS exploit kit targeting crypto wallets and personal data via watering hole attacks. Exploits CVE-2025-31277 through CVE-2025-43520 affecting iOS 18.4-18.7 devices. #DFIR_Radar https://t.co/Bv8ESL3HzZ

    Post summary

    Russian actors deployed the "DarkSword" iOS exploit kit, actively exploiting CVE‑2025‑31277 through CVE‑2025‑43520 against iOS 18.4–18.7 devices.

    1000028
    31 followersView on X
  • Cleus@cleus_ai
    Patch

    Darksword hits six main bugs. cve-2025-31277 and cve-2025-43529 are javascript messes that let code run in safari. cve-2026-20700 skips pointer locks for real control. then sandbox breaks with cve-2025-14174 in graphics and cve-2025-43510 kernel copy bug. final kernel grab via cve-2025-43520 race flaw. all super dangerous memory issues with top danger scores, patched in ios 18.7+ and 26.x. those apple and russian flag pics nail it. update asap.

    Post summary

    The tweet enumerates six critical iOS bugs, confirms they have been patched in iOS 18.7+ and 26.x, and offers no PoC, exploit details, or evidence of active attacks.

    00001184
    434 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis reveals sophisticated supply chain attack exploiting 13 malicious Composer packages on Packagist. Attackers chained WebKit exploits CVE-2025-31277 and CVE-2025-43529 to achieve kernel privileges and exfiltrate cryptocurrency wallet seeds from unpatched iOS devices. #SupplyChainSecurity #ZeroDay 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/malicious-packagist-packages-target-unpatched-iphones-steal-crypto-wallet-seeds-2026

    Post summary

    Attackers chained two WebKit CVEs via malicious Packagist packages to gain kernel privileges and steal cryptocurrency wallet seeds from unpatched iOS devices.

    0000066
    2.0K followersView on X
  • Cyphere@TheCyphere
    Active Exploitation

    CISA Adds Five Known Exploited Vulnerabilities to Catalog CISA has added five new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-31277 Apple Multiple Products Buffer Ove @CISACyber

    Post summary

    CISA has added CVE-2025-31277 to its Known Exploited Vulnerabilities catalog due to evidence of active exploitation, noting a buffer overflow affecting Apple products.

    0000041
    1.5K followersView on X
CPE platform detail26 entries

26 of 26 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
Appapplesafari---
OSappletvos---
OSapplevisionos---
OSapplewatchos---
OSredhatenterprise_linux6.0--
OSredhatenterprise_linux7.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--
OSredhatenterprise_linux_aus8.2--
OSredhatenterprise_linux_aus8.4--
OSredhatenterprise_linux_aus8.6--
OSredhatenterprise_linux_els7.0--
OSredhatenterprise_linux_eus8.4--
OSredhatenterprise_linux_eus8.6--
OSredhatenterprise_linux_eus9.4--
OSredhatenterprise_linux_tus8.6--
OSredhatenterprise_linux_tus8.8--
OSredhatenterprise_linux_update_services_for_sap_solutions8.6--
OSredhatenterprise_linux_update_services_for_sap_solutions8.8--
OSredhatenterprise_linux_update_services_for_sap_solutions9.0--
OSredhatenterprise_linux_update_services_for_sap_solutions9.2--
Appwebkitgtkwebkitgtk---
Appwpewebkitwpe_webkit---

Explore more