Apple Ios And Ipados vulnerabilities
1,703 known vulnerabilities affecting apple/ios_and_ipados.
Total CVEs
1,703
CISA KEV
57
actively exploited
Public exploits
17
Exploited in wild
72
Severity breakdown
CRITICAL106HIGH646MEDIUM828LOW123
Vulnerabilities
Page 10 of 86
CVE-2021-31008P3HIGHCVSS 8.8≥ unspecified, < 152021-08-24
CVE-2021-31008 [HIGH] CWE-843 CVE-2021-31008: A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 15
A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 15.1, tvOS 15.1, iOS 15 and iPadOS 15, macOS Monterey 12.0.1, watchOS 8.1. Processing maliciously crafted web content may lead to code execution.
nvd
CVE-2020-9932P3HIGHCVSS 8.8≥ unspecified, < 13.12020-10-27
CVE-2020-9932 [HIGH] CWE-787 CVE-2020-9932: A memory corruption issue was addressed with improved validation. This issue is fixed in Safari 13.0
A memory corruption issue was addressed with improved validation. This issue is fixed in Safari 13.0.1, iOS 13.1 and iPadOS 13.1, tvOS 13. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2025-31273P3HIGHCVSS 8.8fixed in 18.62025-07-30
CVE-2025-31273 [HIGH] CWE-119 CVE-2025-31273: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2025-43433P3HIGHCVSS 8.8fixed in 18.7.2fixed in 26.12025-11-04
CVE-2025-43433 [HIGH] CWE-787 CVE-2025-43433: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2024-54505P3HIGHCVSS 8.8fixed in 18.22024-12-12
CVE-2024-54505 [HIGH] CWE-843 CVE-2024-54505: A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 18
A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2023-40448P3HIGHCVSS 8.6≥ unspecified, < 17≥ unspecified, < 16.72023-09-27
CVE-2023-40448 [HIGH] CVE-2023-40448: The issue was addressed with improved handling of protocols. This issue is fixed in tvOS 17, iOS 16.
The issue was addressed with improved handling of protocols. This issue is fixed in tvOS 17, iOS 16.7 and iPadOS 16.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. A remote attacker may be able to break out of Web Content sandbox.
nvd
CVE-2023-41060P3HIGHCVSS 8.8≥ unspecified, < 172024-01-10
CVE-2023-41060 [HIGH] CWE-843 CVE-2023-41060: A type confusion issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14, i
A type confusion issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. A remote user may be able to cause kernel code execution.
nvd
CVE-2023-42833P3HIGHCVSS 8.8≥ unspecified, < 172024-01-10
CVE-2023-42833 [HIGH] CWE-94 CVE-2023-42833: A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14, Safa
A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14, Safari 17, iOS 17 and iPadOS 17. Processing web content may lead to arbitrary code execution.
nvd
CVE-2024-54543P3HIGHCVSS 8.8fixed in 18.22025-01-27
CVE-2024-54543 [HIGH] CWE-787 CVE-2024-54543: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2025-43431P3HIGHCVSS 8.8fixed in 18.7.2fixed in 26.12025-11-04
CVE-2025-43431 [HIGH] CWE-787 CVE-2025-43431: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2026-28955P3HIGHCVSS 8.8fixed in 18.7.9fixed in 26.52026-05-11
CVE-2026-28955 [HIGH] CWE-119 CVE-2026-28955: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2023-32358P3HIGHCVSS 8.8≥ unspecified, < 16.42023-08-14
CVE-2023-32358 [HIGH] CWE-843 CVE-2023-32358: A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.4 and iPadO
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.4 and iPadOS 16.4, macOS Ventura 13.3. Processing web content may lead to arbitrary code execution.
nvd
CVE-2026-28847P3HIGHCVSS 8.8fixed in 18.7.9fixed in 26.52026-05-11
CVE-2026-28847 [HIGH] CWE-119 CVE-2026-28847: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-64757P3HIGHCVSS 8.8fixed in 18.7.10fixed in 26.62026-07-27
CVE-2026-64757 [HIGH] CWE-119 CVE-2026-64757: A memory corruption issue was addressed with improved state management. This issue is fixed in Safar
A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2026-28931P3HIGHCVSS 8.8fixed in 26.62026-07-27
CVE-2026-28931 [HIGH] CWE-120 CVE-2026-28931: A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and i
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. Connecting to a malicious NFS server may lead to kernel memory corruption.
nvd
CVE-2025-43202P3HIGHCVSS 8.8fixed in 18.62026-04-02
CVE-2025-43202 [HIGH] CWE-787 CVE-2025-43202: This issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 1
This issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6. Processing a file may lead to memory corruption.
nvd
CVE-2026-28947P3HIGHCVSS 8.8fixed in 18.7.10fixed in 26.52026-05-11
CVE-2026-28947 [HIGH] CWE-416 CVE-2026-28947: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2021-30984P3HIGHCVSS 7.5≥ unspecified, < 15.22021-08-24
CVE-2021-30984 [HIGH] CWE-362 CVE-2021-30984: A race condition was addressed with improved state handling. This issue is fixed in tvOS 15.2, macOS
A race condition was addressed with improved state handling. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2025-24230P3CRITICALCVSS 9.8fixed in 18.42025-03-31
CVE-2025-24230 [CRITICAL] CWE-125 CVE-2025-24230: An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. Playing a malicious audio file may lead to an unexpected app termination.
nvd
CVE-2025-24211P3CRITICALCVSS 9.8fixed in 18.42025-03-31
CVE-2025-24211 [CRITICAL] CWE-400 CVE-2025-24211: This issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 1
This issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4. Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory.
nvd