Apple Ios 26.1 And Ipados vulnerabilities
62 known vulnerabilities affecting apple/ios_26.1_and_ipados.
Total CVEs
62
CISA KEV
2
actively exploited
Public exploits
0
Exploited in wild
2
Severity breakdown
HIGH16MEDIUM41LOW5
Vulnerabilities
Page 3 of 4
CVE-2025-43432P4MEDIUMCVSS 4.3v26.12025-11-03
CVE-2025-43432 [MEDIUM] CVE-2025-43432: iOS 26.1 and iPadOS 26.1
Apple Security Update: About the security content of iOS 26.1 and iPadOS 26.1
Product: iOS 26.1 and iPadOS
Version: 26.1
CVE: CVE-2025-43432
Component: WebKit
Impact: Processing maliciously crafted web content may lead to an unexpected process crash
Description: A use-after-free issue was addressed with improved memory management.
apple
CVE-2025-43435P4MEDIUMCVSS 4.3v26.12025-11-03
CVE-2025-43435 [MEDIUM] CVE-2025-43435: iOS 26.1 and iPadOS 26.1
Apple Security Update: About the security content of iOS 26.1 and iPadOS 26.1
Product: iOS 26.1 and iPadOS
Version: 26.1
CVE: CVE-2025-43435
Component: WebKit
Impact: Processing maliciously crafted web content may lead to an unexpected process crash
Description: The issue was addressed with improved memory handling.
apple
CVE-2025-43443P4MEDIUMCVSS 4.3v26.12025-11-03
CVE-2025-43443 [MEDIUM] CVE-2025-43443: iOS 26.1 and iPadOS 26.1
Apple Security Update: About the security content of iOS 26.1 and iPadOS 26.1
Product: iOS 26.1 and iPadOS
Version: 26.1
CVE: CVE-2025-43443
Component: WebKit
Impact: Processing maliciously crafted web content may lead to an unexpected process crash
Description: This issue was addressed with improved checks.
apple
CVE-2025-43458P4MEDIUMCVSS 4.3v26.12025-11-03
CVE-2025-43458 [MEDIUM] CVE-2025-43458: iOS 26.1 and iPadOS 26.1
Apple Security Update: About the security content of iOS 26.1 and iPadOS 26.1
Product: iOS 26.1 and iPadOS
Version: 26.1
CVE: CVE-2025-43458
Component: WebKit
Impact: Processing maliciously crafted web content may lead to an unexpected process crash
Description: This issue was addressed through improved state management.
apple
CVE-2025-43398P4MEDIUMCVSS 5.5v26.12025-11-03
CVE-2025-43398 [MEDIUM] CVE-2025-43398: iOS 26.1 and iPadOS 26.1
Apple Security Update: About the security content of iOS 26.1 and iPadOS 26.1
Product: iOS 26.1 and iPadOS
Version: 26.1
CVE: CVE-2025-43398
Component: Kernel
Impact: An app may be able to cause unexpected system termination
Description: The issue was addressed with improved memory handling.
apple
CVE-2025-43447P4MEDIUMCVSS 5.5v26.12025-11-03
CVE-2025-43447 [MEDIUM] CVE-2025-43447: iOS 26.1 and iPadOS 26.1
Apple Security Update: About the security content of iOS 26.1 and iPadOS 26.1
Product: iOS 26.1 and iPadOS
Version: 26.1
CVE: CVE-2025-43447
Impact: An app may be able to cause unexpected system termination or corrupt kernel memory
Description: The issue was addressed with improved memory handling.
apple
CVE-2025-43425P4MEDIUMCVSS 4.3v26.12025-11-03
CVE-2025-43425 [MEDIUM] CVE-2025-43425: iOS 26.1 and iPadOS 26.1
Apple Security Update: About the security content of iOS 26.1 and iPadOS 26.1
Product: iOS 26.1 and iPadOS
Version: 26.1
CVE: CVE-2025-43425
Component: WebKit
Impact: Processing maliciously crafted web content may lead to an unexpected process crash
Description: The issue was addressed with improved memory handling.
apple
CVE-2025-43427P4MEDIUMCVSS 4.3v26.12025-11-03
CVE-2025-43427 [MEDIUM] CVE-2025-43427: iOS 26.1 and iPadOS 26.1
Apple Security Update: About the security content of iOS 26.1 and iPadOS 26.1
Product: iOS 26.1 and iPadOS
Version: 26.1
CVE: CVE-2025-43427
Component: WebKit
Impact: Processing maliciously crafted web content may lead to an unexpected process crash
Description: This issue was addressed through improved state management.
apple
CVE-2025-43421P4MEDIUMCVSS 4.3v26.12025-11-03
CVE-2025-43421 [MEDIUM] CVE-2025-43421: iOS 26.1 and iPadOS 26.1
Apple Security Update: About the security content of iOS 26.1 and iPadOS 26.1
Product: iOS 26.1 and iPadOS
Version: 26.1
CVE: CVE-2025-43421
Component: WebKit
Impact: Processing maliciously crafted web content may lead to an unexpected process crash
Description: Multiple issues were addressed by disabling array allocation sinking.
apple
CVE-2025-43503P4MEDIUMCVSS 4.3v26.12025-11-03
CVE-2025-43503 [MEDIUM] CVE-2025-43503: iOS 26.1 and iPadOS 26.1
Apple Security Update: About the security content of iOS 26.1 and iPadOS 26.1
Product: iOS 26.1 and iPadOS
Version: 26.1
CVE: CVE-2025-43503
Component: Safari
Impact: Visiting a malicious website may lead to user interface spoofing
Description: An inconsistent user interface issue was addressed with improved state management.
apple
CVE-2025-46316P4MEDIUMCVSS 4.3v26.12025-11-03
CVE-2025-46316 [MEDIUM] CVE-2025-46316: iOS 26.1 and iPadOS 26.1
Apple Security Update: About the security content of iOS 26.1 and iPadOS 26.1
Product: iOS 26.1 and iPadOS
Version: 26.1
CVE: CVE-2025-46316
Component: QuickLook
Impact: Processing a maliciously crafted Pages document may result in unexpected termination or disclosure of process memory
Description: An out-of-bounds read was addressed with improved input validation.
apple
CVE-2025-43460P4MEDIUMCVSS 4.6v26.12025-11-03
CVE-2025-43460 [MEDIUM] CVE-2025-43460: iOS 26.1 and iPadOS 26.1
Apple Security Update: About the security content of iOS 26.1 and iPadOS 26.1
Product: iOS 26.1 and iPadOS
Version: 26.1
CVE: CVE-2025-43460
Component: Status Bar
Impact: An attacker with physical access to a locked device may be able to view sensitive user information
Description: A logic issue was addressed with improved checks.
apple
CVE-2025-43392P4MEDIUMCVSS 4.3v26.12025-11-03
CVE-2025-43392 [MEDIUM] CVE-2025-43392: iOS 26.1 and iPadOS 26.1
Apple Security Update: About the security content of iOS 26.1 and iPadOS 26.1
Product: iOS 26.1 and iPadOS
Version: 26.1
CVE: CVE-2025-43392
Component: WebKit Canvas
Impact: A website may exfiltrate image data cross-origin
Description: The issue was addressed with improved handling of caches.
apple
CVE-2025-43493P4MEDIUMCVSS 4.3v26.12025-11-03
CVE-2025-43493 [MEDIUM] CVE-2025-43493: iOS 26.1 and iPadOS 26.1
Apple Security Update: About the security content of iOS 26.1 and iPadOS 26.1
Product: iOS 26.1 and iPadOS
Version: 26.1
CVE: CVE-2025-43493
Component: Safari
Impact: Visiting a malicious website may lead to address bar spoofing
Description: The issue was addressed with improved checks.
apple
CVE-2025-43418P4MEDIUMCVSS 4.6v26.12025-11-03
CVE-2025-43418 [MEDIUM] CVE-2025-43418: iOS 26.1 and iPadOS 26.1
Apple Security Update: About the security content of iOS 26.1 and iPadOS 26.1
Product: iOS 26.1 and iPadOS
Version: 26.1
CVE: CVE-2025-43418
Component: Spotlight
Impact: An attacker with physical access to a locked device may be able to view sensitive user information
Description: This issue was addressed by restricting options offered on a locked device.
apple
CVE-2025-43452P4MEDIUMCVSS 4.6v26.12025-11-03
CVE-2025-43452 [MEDIUM] CVE-2025-43452: iOS 26.1 and iPadOS 26.1
Apple Security Update: About the security content of iOS 26.1 and iPadOS 26.1
Product: iOS 26.1 and iPadOS
Version: 26.1
CVE: CVE-2025-43452
Component: Text Input
Impact: Keyboard suggestions may display sensitive information on the lock screen
Description: This issue was addressed by restricting options offered on a locked device.
apple
CVE-2025-43422P4MEDIUMCVSS 4.6v26.12025-11-03
CVE-2025-43422 [MEDIUM] CVE-2025-43422: iOS 26.1 and iPadOS 26.1
Apple Security Update: About the security content of iOS 26.1 and iPadOS 26.1
Product: iOS 26.1 and iPadOS
Version: 26.1
CVE: CVE-2025-43422
Component: Stolen Device Protection
Impact: An attacker with physical access to a device may be able to disable Stolen Device Protection
Description: The issue was addressed by adding additional logic.
apple
CVE-2025-43294P4LOWCVSS 3.3v26.12025-11-03
CVE-2025-43294 [LOW] CVE-2025-43294: iOS 26.1 and iPadOS 26.1
Apple Security Update: About the security content of iOS 26.1 and iPadOS 26.1
Product: iOS 26.1 and iPadOS
Version: 26.1
CVE: CVE-2025-43294
Component: MallocStackLogging
Impact: An app may be able to access sensitive user data
Description: An issue existed in the handling of environment variables. This issue was addressed with improved validation.
apple
CVE-2025-43437P4LOWCVSS 3.3v26.12025-11-03
CVE-2025-43437 [LOW] CVE-2025-43437: iOS 26.1 and iPadOS 26.1
Apple Security Update: About the security content of iOS 26.1 and iPadOS 26.1
Product: iOS 26.1 and iPadOS
Version: 26.1
CVE: CVE-2025-43437
Component: Managed Configuration
Impact: An app may be able to fingerprint the user
Description: An information disclosure issue was addressed with improved privacy controls.
apple
CVE-2025-43442P4LOWCVSS 3.3v26.12025-11-03
CVE-2025-43442 [LOW] CVE-2025-43442: iOS 26.1 and iPadOS 26.1
Apple Security Update: About the security content of iOS 26.1 and iPadOS 26.1
Product: iOS 26.1 and iPadOS
Version: 26.1
CVE: CVE-2025-43442
Component: Accessibility
Impact: An app may be able to identify what other apps a user has installed
Description: A permissions issue was addressed with additional restrictions.
apple