Apple Ios 26.2 And Ipados vulnerabilities
38 known vulnerabilities affecting apple/ios_26.2_and_ipados.
Total CVEs
38
CISA KEV
2
actively exploited
Public exploits
2
Exploited in wild
4
Severity breakdown
CRITICAL1HIGH7MEDIUM24LOW6
Vulnerabilities
Page 1 of 2
CVE-2025-14174P1HIGHCVSS 8.8KEVPoCv26.22025-12-12
CVE-2025-14174 [HIGH] CVE-2025-14174: iOS 26.2 and iPadOS 26.2
Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2
Product: iOS 26.2 and iPadOS
Version: 26.2
CVE: CVE-2025-14174
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-1417
apple
CVE-2025-43529P1HIGHCVSS 8.8KEVPoCv26.22025-12-12
CVE-2025-43529 [HIGH] CVE-2025-43529: iOS 26.2 and iPadOS 26.2
Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2
Product: iOS 26.2 and iPadOS
Version: 26.2
CVE: CVE-2025-43529
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-1417
apple
CVE-2025-43542P2HIGHCVSS 7.5Exploitedv26.22025-12-12
CVE-2025-43542 [HIGH] CVE-2025-43542: iOS 26.2 and iPadOS 26.2
Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2
Product: iOS 26.2 and iPadOS
Version: 26.2
CVE: CVE-2025-43542
Component: FaceTime
Impact: Password fields may be unintentionally revealed when remotely controlling a device over FaceTime
Description: This issue was addressed with improved state management.
apple
CVE-2025-43532P2LOWCVSS 2.8Exploitedv26.22025-12-12
CVE-2025-43532 [LOW] CVE-2025-43532: iOS 26.2 and iPadOS 26.2
Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2
Product: iOS 26.2 and iPadOS
Version: 26.2
CVE: CVE-2025-43532
Component: Foundation
Impact: Processing malicious data may lead to unexpected app termination
Description: A memory corruption issue was addressed with improved bounds checking.
apple
CVE-2025-43539P3HIGHCVSS 8.8v26.22025-12-12
CVE-2025-43539 [HIGH] CVE-2025-43539: iOS 26.2 and iPadOS 26.2
Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2
Product: iOS 26.2 and iPadOS
Version: 26.2
CVE: CVE-2025-43539
Component: AppleJPEG
Impact: Processing a file may lead to memory corruption
Description: The issue was addressed with improved bounds checks.
apple
CVE-2025-43428P3CRITICALCVSS 9.8v26.22025-12-12
CVE-2025-43428 [CRITICAL] CVE-2025-43428: iOS 26.2 and iPadOS 26.2
Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2
Product: iOS 26.2 and iPadOS
Version: 26.2
CVE: CVE-2025-43428
Component: Photos
Impact: Photos in the Hidden Photos Album may be viewed without authentication
Description: A configuration issue was addressed with additional restrictions.
apple
CVE-2024-7264P3MEDIUMCVSS 6.5v26.22025-12-12
CVE-2024-7264 [MEDIUM] CVE-2024-7264: iOS 26.2 and iPadOS 26.2
Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2
Product: iOS 26.2 and iPadOS
Version: 26.2
CVE: CVE-2024-7264
Component: CVE-2024-7264
apple
CVE-2025-46285P3HIGHCVSS 7.8v26.22025-12-12
CVE-2025-46285 [HIGH] CVE-2025-46285: iOS 26.2 and iPadOS 26.2
Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2
Product: iOS 26.2 and iPadOS
Version: 26.2
CVE: CVE-2025-46285
Component: Kernel
Impact: An app may be able to gain root privileges
Description: An integer overflow was addressed by adopting 64-bit timestamps.
apple
CVE-2025-9086P3HIGHCVSS 7.5v26.22025-12-12
CVE-2025-9086 [HIGH] CVE-2025-9086: iOS 26.2 and iPadOS 26.2
Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2
Product: iOS 26.2 and iPadOS
Version: 26.2
CVE: CVE-2025-9086
Component: CVE-2025-9086
apple
CVE-2025-46290P3HIGHCVSS 7.5v26.22025-12-12
CVE-2025-46290 [HIGH] CVE-2025-46290: iOS 26.2 and iPadOS 26.2
Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2
Product: iOS 26.2 and iPadOS
Version: 26.2
CVE: CVE-2025-46290
Component: Security
Impact: A remote attacker may be able to cause a denial-of-service
Description: A logic issue was addressed with improved checks.
apple
CVE-2025-43541P4MEDIUMCVSS 4.3v26.22025-12-12
CVE-2025-43541 [MEDIUM] CVE-2025-43541: iOS 26.2 and iPadOS 26.2
Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2
Product: iOS 26.2 and iPadOS
Version: 26.2
CVE: CVE-2025-43541
Component: WebKit
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: A type confusion issue was addressed with improved state handling.
apple
CVE-2025-46287P4MEDIUMCVSS 6.5v26.22025-12-12
CVE-2025-46287 [MEDIUM] CVE-2025-46287: iOS 26.2 and iPadOS 26.2
Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2
Product: iOS 26.2 and iPadOS
Version: 26.2
CVE: CVE-2025-46287
Component: Calling Framework
Impact: An attacker may be able to spoof their FaceTime caller ID
Description: An inconsistent user interface issue was addressed with improved state management.
apple
CVE-2025-43511P4MEDIUMCVSS 6.5v26.22025-12-12
CVE-2025-43511 [MEDIUM] CVE-2025-43511: iOS 26.2 and iPadOS 26.2
Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2
Product: iOS 26.2 and iPadOS
Version: 26.2
CVE: CVE-2025-43511
Component: WebKit Web Inspector
Impact: Processing maliciously crafted web content may lead to an unexpected process crash
Description: A use-after-free issue was addressed with improved memory management.
apple
CVE-2025-43538P4MEDIUMCVSS 5.5v26.22025-12-12
CVE-2025-43538 [MEDIUM] CVE-2025-43538: iOS 26.2 and iPadOS 26.2
Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2
Product: iOS 26.2 and iPadOS
Version: 26.2
CVE: CVE-2025-43538
Component: Screen Time
Impact: An app may be able to access sensitive user data
Description: A logging issue was addressed with improved data redaction.
apple
CVE-2025-46298P4MEDIUMCVSS 6.5v26.22025-12-12
CVE-2025-46298 [MEDIUM] CVE-2025-46298: iOS 26.2 and iPadOS 26.2
Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2
Product: iOS 26.2 and iPadOS
Version: 26.2
CVE: CVE-2025-46298
Component: WebKit
Impact: Processing maliciously crafted web content may lead to an unexpected process crash
Description: The issue was addressed with improved memory handling.
apple
CVE-2025-43534P4MEDIUMCVSS 6.8v26.22025-12-12
CVE-2025-43534 [MEDIUM] CVE-2025-43534: iOS 26.2 and iPadOS 26.2
Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2
Product: iOS 26.2 and iPadOS
Version: 26.2
CVE: CVE-2025-43534
Component: Icons
Impact: An app may be able to identify what other apps a user has installed
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-5918P4LOWCVSS 3.9v26.22025-12-12
CVE-2025-5918 [LOW] CVE-2025-5918: iOS 26.2 and iPadOS 26.2
Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2
Product: iOS 26.2 and iPadOS
Version: 26.2
CVE: CVE-2025-5918
Component: CVE-2025-5918
apple
CVE-2025-43537P4MEDIUMCVSS 5.5v26.22025-12-12
CVE-2025-43537 [MEDIUM] CVE-2025-43537: iOS 26.2 and iPadOS 26.2
Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2
Product: iOS 26.2 and iPadOS
Version: 26.2
CVE: CVE-2025-43537
Component: Books
Impact: Restoring a maliciously crafted backup file may lead to modification of protected system files
Description: A path handling issue was addressed with improved validation.
apple
CVE-2025-46276P4MEDIUMCVSS 5.5v26.22025-12-12
CVE-2025-46276 [MEDIUM] CVE-2025-46276: iOS 26.2 and iPadOS 26.2
Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2
Product: iOS 26.2 and iPadOS
Version: 26.2
CVE: CVE-2025-46276
Component: Messages
Impact: An app may be able to access sensitive user data
Description: An information disclosure issue was addressed with improved privacy controls.
apple
CVE-2025-43475P4MEDIUMCVSS 5.5v26.22025-12-12
CVE-2025-43475 [MEDIUM] CVE-2025-43475: iOS 26.2 and iPadOS 26.2
Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2
Product: iOS 26.2 and iPadOS
Version: 26.2
CVE: CVE-2025-43475
Component: MediaExperience
Impact: An app may be able to access user-sensitive data
Description: A logging issue was addressed with improved data redaction.
apple
1 / 2Next →