HIGHVulnerability
Verified
Global

CISA KEV: Apple Multiple Products — Apple Multiple Products Buffer Overflow Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory corruption.

Analysis

Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory corruption. Added to CISA Known Exploited Vulnerabilities catalog on 2026-03-20. Remediation due: 2026-04-03.

Indicators of Compromise (1)

CVE (1)
CVE-2025-31277
Source Attribution

Originally published by CISA KEV on Mar 20, 2026. Verified by: CISA.

Related Threats

CRITICALVulnerability

NVD CRITICAL: CVE-2026-73053 — SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in th...

SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the renderer with Node integration enabled, achieving arbitrary code execution on the host system.

CVE-2026-73053
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-73052 — SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and...

SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary JavaScript when users open the sort menu, with Node integration enabled in the desktop client enabling code execution.

CVE-2026-73052
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-73050 — SiYuan versions before v3.7.4 fail to validate or escape the color field in attr...

SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. Attackers can inject event-handler attributes by including quotation marks in the color value, executing arbitrary JavaScript when viewing databases containing the malicious select field.

CVE-2026-73050
NIST NVD