CVE-2025-31215

Overview

Advisory: Apple Security Advisory

Impact:

Description: Processing maliciously crafted web content may lead to an unexpected process crash

Researchers: Jiming Wang and Jikai Ren

Attribute Value
CVE CVE-2025-31215
Bugzilla 288814
Component JSC
Bug Class LogicError
Severity medium
Commit ac09d743b1828ad9…
Advisory Apple Advisory

Root Cause Analysis

The issue was addressed with improved checks.

Files Changed

Source Files

  • Source/JavaScriptCore/dfg/DFGAbstractInterpreterInlines.h
  • Source/JavaScriptCore/ftl/FTLLowerDFGToB3.cpp

Test Files

  • JSTests/stress/dfg-ai-should-reduce-new-array-with-spread-structures.js