Apple Ios 26.3 And Ipados vulnerabilities
46 known vulnerabilities affecting apple/ios_26.3_and_ipados.
Total CVEs
46
CISA KEV
3
actively exploited
Public exploits
3
Exploited in wild
3
Severity breakdown
CRITICAL1HIGH17MEDIUM25LOW3
Vulnerabilities
Page 2 of 3
CVE-2026-20680P4MEDIUMCVSS 6.5v26.32026-02-11
CVE-2026-20680 [MEDIUM] CVE-2026-20680: iOS 26.3 and iPadOS 26.3
Apple Security Update: About the security content of iOS 26.3 and iPadOS 26.3
Product: iOS 26.3 and iPadOS
Version: 26.3
CVE: CVE-2026-20680
Component: Spotlight
Impact: A sandboxed app may be able to access sensitive user data
Description: The issue was addressed with additional restrictions on the observability of app states.
apple
CVE-2026-20686P4MEDIUMCVSS 5.3v26.32026-02-11
CVE-2026-20686 [MEDIUM] CVE-2026-20686: iOS 26.3 and iPadOS 26.3
Apple Security Update: About the security content of iOS 26.3 and iPadOS 26.3
Product: iOS 26.3 and iPadOS
Version: 26.3
CVE: CVE-2026-20686
Component: Contacts
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with improved input validation.
apple
CVE-2026-20682P4MEDIUMCVSS 5.3v26.32026-02-11
CVE-2026-20682 [MEDIUM] CVE-2026-20682: iOS 26.3 and iPadOS 26.3
Apple Security Update: About the security content of iOS 26.3 and iPadOS 26.3
Product: iOS 26.3 and iPadOS
Version: 26.3
CVE: CVE-2026-20682
Component: Screenshots
Impact: An attacker may be able to discover a user’s deleted notes
Description: A logic issue was addressed with improved state management.
apple
CVE-2026-20676P4MEDIUMCVSS 5.3v26.32026-02-11
CVE-2026-20676 [MEDIUM] CVE-2026-20676: iOS 26.3 and iPadOS 26.3
Apple Security Update: About the security content of iOS 26.3 and iPadOS 26.3
Product: iOS 26.3 and iPadOS
Version: 26.3
CVE: CVE-2026-20676
Component: WebKit
Impact: A website may be able to track users through Safari web extensions
Description: This issue was addressed through improved state management.
apple
CVE-2026-20675P4MEDIUMCVSS 5.5v26.32026-02-11
CVE-2026-20675 [MEDIUM] CVE-2026-20675: iOS 26.3 and iPadOS 26.3
Apple Security Update: About the security content of iOS 26.3 and iPadOS 26.3
Product: iOS 26.3 and iPadOS
Version: 26.3
CVE: CVE-2026-20675
Component: ImageIO
Impact: Processing a maliciously crafted image may lead to disclosure of user information
Description: The issue was addressed with improved bounds checks.
apple
CVE-2026-20634P4MEDIUMCVSS 5.5v26.32026-02-11
CVE-2026-20634 [MEDIUM] CVE-2026-20634: iOS 26.3 and iPadOS 26.3
Apple Security Update: About the security content of iOS 26.3 and iPadOS 26.3
Product: iOS 26.3 and iPadOS
Version: 26.3
CVE: CVE-2026-20634
Component: ImageIO
Impact: Processing a maliciously crafted image may result in disclosure of process memory
Description: The issue was addressed with improved memory handling.
apple
CVE-2026-20694P4MEDIUMCVSS 5.5v26.32026-02-11
CVE-2026-20694 [MEDIUM] CVE-2026-20694: iOS 26.3 and iPadOS 26.3
Apple Security Update: About the security content of iOS 26.3 and iPadOS 26.3
Product: iOS 26.3 and iPadOS
Version: 26.3
CVE: CVE-2026-20694
Component: MigrationKit
Impact: An app may be able to access user-sensitive data
Description: This issue was addressed with improved handling of symlinks.
apple
CVE-2026-20678P4MEDIUMCVSS 5.5v26.32026-02-11
CVE-2026-20678 [MEDIUM] CVE-2026-20678: iOS 26.3 and iPadOS 26.3
Apple Security Update: About the security content of iOS 26.3 and iPadOS 26.3
Product: iOS 26.3 and iPadOS
Version: 26.3
CVE: CVE-2026-20678
Component: Sandbox Profiles
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state management.
apple
CVE-2026-20668P4MEDIUMCVSS 5.5v26.32026-02-11
CVE-2026-20668 [MEDIUM] CVE-2026-20668: iOS 26.3 and iPadOS 26.3
Apple Security Update: About the security content of iOS 26.3 and iPadOS 26.3
Product: iOS 26.3 and iPadOS
Version: 26.3
CVE: CVE-2026-20668
Component: Focus
Impact: An app may be able to access sensitive user data
Description: A logging issue was addressed with improved data redaction.
apple
CVE-2026-20653P4MEDIUMCVSS 5.5v26.32026-02-11
CVE-2026-20653 [MEDIUM] CVE-2026-20653: iOS 26.3 and iPadOS 26.3
Apple Security Update: About the security content of iOS 26.3 and iPadOS 26.3
Product: iOS 26.3 and iPadOS
Version: 26.3
CVE: CVE-2026-20653
Component: Shortcuts
Impact: An app may be able to access sensitive user data
Description: A parsing issue in the handling of directory paths was addressed with improved path validation.
apple
CVE-2026-20627P4MEDIUMCVSS 5.5v26.32026-02-11
CVE-2026-20627 [MEDIUM] CVE-2026-20627: iOS 26.3 and iPadOS 26.3
Apple Security Update: About the security content of iOS 26.3 and iPadOS 26.3
Product: iOS 26.3 and iPadOS
Version: 26.3
CVE: CVE-2026-20627
Component: CoreServices
Impact: An app may be able to access sensitive user data
Description: An issue existed in the handling of environment variables. This issue was addressed with improved validation.
apple
CVE-2026-20655P4MEDIUMCVSS 5.5v26.32026-02-11
CVE-2026-20655 [MEDIUM] CVE-2026-20655: iOS 26.3 and iPadOS 26.3
Apple Security Update: About the security content of iOS 26.3 and iPadOS 26.3
Product: iOS 26.3 and iPadOS
Version: 26.3
CVE: CVE-2026-20655
Component: Live Captions
Impact: An attacker with physical access to a locked device may be able to view sensitive user information
Description: An authorization issue was addressed with improved state management.
apple
CVE-2026-20637P4MEDIUMCVSS 6.2v26.32026-02-11
CVE-2026-20637 [MEDIUM] CVE-2026-20637: iOS 26.3 and iPadOS 26.3
Apple Security Update: About the security content of iOS 26.3 and iPadOS 26.3
Product: iOS 26.3 and iPadOS
Version: 26.3
CVE: CVE-2026-20637
Component: AppleKeyStore
Impact: An app may be able to cause unexpected system termination
Description: A use after free issue was addressed with improved memory management.
apple
CVE-2026-20608P4MEDIUMCVSS 5.5v26.32026-02-11
CVE-2026-20608 [MEDIUM] CVE-2026-20608: iOS 26.3 and iPadOS 26.3
Apple Security Update: About the security content of iOS 26.3 and iPadOS 26.3
Product: iOS 26.3 and iPadOS
Version: 26.3
CVE: CVE-2026-20608
Component: WebKit
Impact: Processing maliciously crafted web content may lead to an unexpected process crash
Description: This issue was addressed through improved state management.
apple
CVE-2026-20638P4MEDIUMCVSS 5.5v26.32026-02-11
CVE-2026-20638 [MEDIUM] CVE-2026-20638: iOS 26.3 and iPadOS 26.3
Apple Security Update: About the security content of iOS 26.3 and iPadOS 26.3
Product: iOS 26.3 and iPadOS
Version: 26.3
CVE: CVE-2026-20638
Component: Call History
Impact: A user with Live Caller ID app extensions turned off could have identifying information leaked to the extensions
Description: A logic issue was addressed with improved checks.
apple
CVE-2026-20635P4MEDIUMCVSS 4.3v26.32026-02-11
CVE-2026-20635 [MEDIUM] CVE-2026-20635: iOS 26.3 and iPadOS 26.3
Apple Security Update: About the security content of iOS 26.3 and iPadOS 26.3
Product: iOS 26.3 and iPadOS
Version: 26.3
CVE: CVE-2026-20635
Component: WebKit
Impact: Processing maliciously crafted web content may lead to an unexpected process crash
Description: The issue was addressed with improved memory handling.
apple
CVE-2026-20621P4MEDIUMCVSS 5.5v26.32026-02-11
CVE-2026-20621 [MEDIUM] CVE-2026-20621: iOS 26.3 and iPadOS 26.3
Apple Security Update: About the security content of iOS 26.3 and iPadOS 26.3
Product: iOS 26.3 and iPadOS
Version: 26.3
CVE: CVE-2026-20621
Component: Wi-Fi
Impact: An app may be able to cause unexpected system termination or corrupt kernel memory
Description: The issue was addressed with improved memory handling.
apple
CVE-2026-20654P4MEDIUMCVSS 5.5v26.32026-02-11
CVE-2026-20654 [MEDIUM] CVE-2026-20654: iOS 26.3 and iPadOS 26.3
Apple Security Update: About the security content of iOS 26.3 and iPadOS 26.3
Product: iOS 26.3 and iPadOS
Version: 26.3
CVE: CVE-2026-20654
Component: Kernel
Impact: An app may be able to cause unexpected system termination
Description: The issue was addressed with improved memory handling.
apple
CVE-2026-20640P4MEDIUMCVSS 4.6v26.32026-02-11
CVE-2026-20640 [MEDIUM] CVE-2026-20640: iOS 26.3 and iPadOS 26.3
Apple Security Update: About the security content of iOS 26.3 and iPadOS 26.3
Product: iOS 26.3 and iPadOS
Version: 26.3
CVE: CVE-2026-20640
Component: UIKit
Impact: An attacker with physical access to iPhone may be able to take and view screenshots of sensitive data from the iPhone during iPhone Mirroring with Mac
Description: An inconsistent user interface issue was addressed with improved state management.
apple
CVE-2026-20645P4MEDIUMCVSS 4.6v26.32026-02-11
CVE-2026-20645 [MEDIUM] CVE-2026-20645: iOS 26.3 and iPadOS 26.3
Apple Security Update: About the security content of iOS 26.3 and iPadOS 26.3
Product: iOS 26.3 and iPadOS
Version: 26.3
CVE: CVE-2026-20645
Component: Accessibility
Impact: An attacker with physical access to a locked device may be able to view sensitive user information
Description: An inconsistent user interface issue was addressed with improved state management.
apple