cbcvebase.

Apple Ios 26.2 And Ipados vulnerabilities

38 known vulnerabilities affecting apple/ios_26.2_and_ipados.

Total CVEs
38
CISA KEV
2
actively exploited
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH7MEDIUM24LOW6

Vulnerabilities

Page 1 of 2
CVE-2025-43428CRITICALCVSS 9.8v26.22025-12-12
CVE-2025-43428 [CRITICAL] CVE-2025-43428: iOS 26.2 and iPadOS 26.2 Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2 Product: iOS 26.2 and iPadOS Version: 26.2 CVE: CVE-2025-43428 Component: Photos Impact: Photos in the Hidden Photos Album may be viewed without authentication Description: A configuration issue was addressed with additional restrictions.
apple
CVE-2025-14174HIGHCVSS 8.8KEVv26.22025-12-12
CVE-2025-14174 [HIGH] CVE-2025-14174: iOS 26.2 and iPadOS 26.2 Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2 Product: iOS 26.2 and iPadOS Version: 26.2 CVE: CVE-2025-14174 Component: WebKit Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-1417
apple
CVE-2025-46290HIGHCVSS 7.5v26.22025-12-12
CVE-2025-46290 [HIGH] CVE-2025-46290: iOS 26.2 and iPadOS 26.2 Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2 Product: iOS 26.2 and iPadOS Version: 26.2 CVE: CVE-2025-46290 Component: Security Impact: A remote attacker may be able to cause a denial-of-service Description: A logic issue was addressed with improved checks.
apple
CVE-2025-43539HIGHCVSS 8.8v26.22025-12-12
CVE-2025-43539 [HIGH] CVE-2025-43539: iOS 26.2 and iPadOS 26.2 Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2 Product: iOS 26.2 and iPadOS Version: 26.2 CVE: CVE-2025-43539 Component: AppleJPEG Impact: Processing a file may lead to memory corruption Description: The issue was addressed with improved bounds checks.
apple
CVE-2025-9086HIGHCVSS 7.5v26.22025-12-12
CVE-2025-9086 [HIGH] CVE-2025-9086: iOS 26.2 and iPadOS 26.2 Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2 Product: iOS 26.2 and iPadOS Version: 26.2 CVE: CVE-2025-9086 Component: CVE-2025-9086
apple
CVE-2025-46285HIGHCVSS 7.8v26.22025-12-12
CVE-2025-46285 [HIGH] CVE-2025-46285: iOS 26.2 and iPadOS 26.2 Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2 Product: iOS 26.2 and iPadOS Version: 26.2 CVE: CVE-2025-46285 Component: Kernel Impact: An app may be able to gain root privileges Description: An integer overflow was addressed by adopting 64-bit timestamps.
apple
CVE-2025-43529HIGHCVSS 8.8KEVv26.22025-12-12
CVE-2025-43529 [HIGH] CVE-2025-43529: iOS 26.2 and iPadOS 26.2 Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2 Product: iOS 26.2 and iPadOS Version: 26.2 CVE: CVE-2025-43529 Component: WebKit Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-1417
apple
CVE-2025-43542HIGHCVSS 7.5v26.22025-12-12
CVE-2025-43542 [HIGH] CVE-2025-43542: iOS 26.2 and iPadOS 26.2 Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2 Product: iOS 26.2 and iPadOS Version: 26.2 CVE: CVE-2025-43542 Component: FaceTime Impact: Password fields may be unintentionally revealed when remotely controlling a device over FaceTime Description: This issue was addressed with improved state management.
apple
CVE-2025-43538MEDIUMCVSS 5.5v26.22025-12-12
CVE-2025-43538 [MEDIUM] CVE-2025-43538: iOS 26.2 and iPadOS 26.2 Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2 Product: iOS 26.2 and iPadOS Version: 26.2 CVE: CVE-2025-43538 Component: Screen Time Impact: An app may be able to access sensitive user data Description: A logging issue was addressed with improved data redaction.
apple
CVE-2025-43534MEDIUMCVSS 6.8v26.22025-12-12
CVE-2025-43534 [MEDIUM] CVE-2025-43534: iOS 26.2 and iPadOS 26.2 Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2 Product: iOS 26.2 and iPadOS Version: 26.2 CVE: CVE-2025-43534 Component: Icons Impact: An app may be able to identify what other apps a user has installed Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-43536MEDIUMCVSS 4.3v26.22025-12-12
CVE-2025-43536 [MEDIUM] CVE-2025-43536: iOS 26.2 and iPadOS 26.2 Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2 Product: iOS 26.2 and iPadOS Version: 26.2 CVE: CVE-2025-43536 Component: WebKit Impact: Processing maliciously crafted web content may lead to an unexpected process crash Description: A use-after-free issue was addressed with improved memory management.
apple
CVE-2025-46292MEDIUMCVSS 5.5v26.22025-12-12
CVE-2025-46292 [MEDIUM] CVE-2025-46292: iOS 26.2 and iPadOS 26.2 Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2 Product: iOS 26.2 and iPadOS Version: 26.2 CVE: CVE-2025-46292 Component: Telephony Impact: An app may be able to access user-sensitive data Description: This issue was addressed with additional entitlement checks.
apple
CVE-2025-46302MEDIUMCVSS 5.7v26.22025-12-12
CVE-2025-46302 [MEDIUM] CVE-2025-46302: iOS 26.2 and iPadOS 26.2 Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2 Product: iOS 26.2 and iPadOS Version: 26.2 CVE: CVE-2025-46302 Component: Multi-Touch Impact: A malicious HID device may cause an unexpected process crash Description: The issue was addressed with improved bounds checks.
apple
CVE-2025-43475MEDIUMCVSS 5.5v26.22025-12-12
CVE-2025-43475 [MEDIUM] CVE-2025-43475: iOS 26.2 and iPadOS 26.2 Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2 Product: iOS 26.2 and iPadOS Version: 26.2 CVE: CVE-2025-43475 Component: MediaExperience Impact: An app may be able to access user-sensitive data Description: A logging issue was addressed with improved data redaction.
apple
CVE-2025-43533MEDIUMCVSS 5.7v26.22025-12-12
CVE-2025-43533 [MEDIUM] CVE-2025-43533: iOS 26.2 and iPadOS 26.2 Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2 Product: iOS 26.2 and iPadOS Version: 26.2 CVE: CVE-2025-43533 Component: Multi-Touch Impact: A malicious HID device may cause an unexpected process crash Description: The issue was addressed with improved bounds checks.
apple
CVE-2025-46301MEDIUMCVSS 5.7v26.22025-12-12
CVE-2025-46301 [MEDIUM] CVE-2025-46301: iOS 26.2 and iPadOS 26.2 Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2 Product: iOS 26.2 and iPadOS Version: 26.2 CVE: CVE-2025-46301 Component: Multi-Touch Impact: A malicious HID device may cause an unexpected process crash Description: The issue was addressed with improved bounds checks.
apple
CVE-2025-46300MEDIUMCVSS 5.7v26.22025-12-12
CVE-2025-46300 [MEDIUM] CVE-2025-46300: iOS 26.2 and iPadOS 26.2 Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2 Product: iOS 26.2 and iPadOS Version: 26.2 CVE: CVE-2025-46300 Component: Multi-Touch Impact: A malicious HID device may cause an unexpected process crash Description: The issue was addressed with improved bounds checks.
apple
CVE-2025-43541MEDIUMCVSS 4.3v26.22025-12-12
CVE-2025-43541 [MEDIUM] CVE-2025-43541: iOS 26.2 and iPadOS 26.2 Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2 Product: iOS 26.2 and iPadOS Version: 26.2 CVE: CVE-2025-43541 Component: WebKit Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash Description: A type confusion issue was addressed with improved state handling.
apple
CVE-2025-46286MEDIUMCVSS 4.3v26.22025-12-12
CVE-2025-46286 [MEDIUM] CVE-2025-46286: iOS 26.2 and iPadOS 26.2 Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2 Product: iOS 26.2 and iPadOS Version: 26.2 CVE: CVE-2025-46286 Component: BiometricKit Impact: Restoring from a backup may prevent passcode from being required immediately after Face ID enrollment Description: A logic issue was addressed with improved validation.
apple
CVE-2024-7264MEDIUMCVSS 6.5v26.22025-12-12
CVE-2024-7264 [MEDIUM] CVE-2024-7264: iOS 26.2 and iPadOS 26.2 Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2 Product: iOS 26.2 and iPadOS Version: 26.2 CVE: CVE-2024-7264 Component: CVE-2024-7264
apple
Apple Ios 26.2 And Ipados vulnerabilities | cvebase