CVE-2025-31277

Overview

Advisory: Apple Security Advisory

Impact:

Description: Processing maliciously crafted web content may lead to memory corruption

Researchers: Yuhao Hu, Yan Kang, Chenggang Wu, and Xiaojie Wei

Attribute Value
CVE CVE-2025-31277
Bugzilla 291745
Component JSC
Bug Class LogicError
Severity medium
Commit 716536ce98d6f8d4…
Advisory Apple Advisory

Root Cause Analysis

The issue was addressed with improved memory handling.

Files Changed

Source Files

  • Source/JavaScriptCore/runtime/JSGlobalObjectInlines.h

Test Files

  • JSTests/stress/regexp-matches-array-should-respect-have-a-bad-time.js