cbcvebase.

Apple Ios And Ipados vulnerabilities

1,703 known vulnerabilities affecting apple/ios_and_ipados.

Total CVEs
1,703
CISA KEV
57
actively exploited
Public exploits
17
Exploited in wild
72
Severity breakdown
CRITICAL106HIGH646MEDIUM828LOW123

Vulnerabilities

Page 12 of 86
CVE-2024-40815P3HIGHCVSS 7.5fixed in 17.62024-07-29
CVE-2024-40815 [HIGH] CWE-362 CVE-2024-40815: A race condition was addressed with additional validation. This issue is fixed in iOS 17.6 and iPadO A race condition was addressed with additional validation. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, watchOS 10.6. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
nvd
CVE-2025-43347P3CRITICALCVSS 9.8fixed in 262025-09-15
CVE-2025-43347 [CRITICAL] CWE-20 CVE-2025-43347: This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26 and iPadOS 2 This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An input validation issue was addressed.
nvd
CVE-2025-43342P3CRITICALCVSS 9.8fixed in 18.7fixed in 262025-09-15
CVE-2025-43342 [CRITICAL] CWE-20 CVE-2025-43342: A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 a A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-43769P3CRITICALCVSS 9.8fixed in 18.7.10fixed in 26.62026-07-27
CVE-2026-43769 [CRITICAL] CWE-190 CVE-2026-43769: An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
nvd
CVE-2026-43802P3CRITICALCVSS 9.8fixed in 18.7.102026-07-27
CVE-2026-43802 [CRITICAL] CWE-787 CVE-2026-43802: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
nvd
CVE-2023-23531P3HIGHCVSS 8.6≥ unspecified, < 16.32023-02-27
CVE-2023-23531 [HIGH] CWE-787 CVE-2023-23531: The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, iO The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.
nvd
CVE-2020-27920P3HIGHCVSS 8.8≥ unspecified, < 14.22021-04-02
CVE-2020-27920 [HIGH] CWE-416 CVE-2020-27920: A use after free issue was addressed with improved memory management. This issue is fixed in macOS B A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, watchOS 7.1, tvOS 14.2. Processing maliciously crafted web content may lead to code execution.
nvd
CVE-2024-54512P3CRITICALCVSS 9.1fixed in 18.22025-01-27
CVE-2024-54512 [CRITICAL] CWE-863 CVE-2024-54512: The issue was addressed by removing the relevant flags. This issue is fixed in iOS 18.2 and iPadOS 1 The issue was addressed by removing the relevant flags. This issue is fixed in iOS 18.2 and iPadOS 18.2, watchOS 11.2. A system binary could be used to fingerprint a user's Apple Account.
nvd
CVE-2026-20616P3HIGHCVSS 8.8fixed in 18.7.52026-02-11
CVE-2026-20616 [HIGH] CWE-787 CVE-2026-20616: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. Processing a maliciously crafted USD file may lead to unexpected app termination.
nvd
CVE-2021-30849P3HIGHCVSS 7.8≥ unspecified, < 14.8≥ unspecified, < 152021-10-19
CVE-2021-30849 [HIGH] CWE-787 CVE-2021-30849: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, watchOS 8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, iTunes 12.12 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2025-30426P3CRITICALCVSS 9.8fixed in 18.42025-03-31
CVE-2025-30426 [CRITICAL] CWE-200 CVE-2025-30426: This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPa This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to enumerate a user's installed apps.
nvd
CVE-2026-43778P3CRITICALCVSS 9.8fixed in 18.7.10fixed in 26.62026-07-27
CVE-2026-43778 [CRITICAL] CWE-416 CVE-2026-43778: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18. A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2026-43809P3CRITICALCVSS 9.8fixed in 18.7.102026-07-27
CVE-2026-43809 [CRITICAL] CWE-125 CVE-2026-43809: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.7.1 An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
nvd
CVE-2026-43757P3CRITICALCVSS 9.8fixed in 18.7.102026-07-27
CVE-2026-43757 [CRITICAL] CWE-125 CVE-2026-43757: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.7.1 An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
nvd
CVE-2026-64762P3CRITICALCVSS 9.8fixed in 18.7.102026-07-27
CVE-2026-64762 [CRITICAL] CWE-125 CVE-2026-64762: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.7.1 An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
nvd
CVE-2026-64751P3CRITICALCVSS 9.8fixed in 26.62026-07-27
CVE-2026-64751 [CRITICAL] CWE-416 CVE-2026-64751: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26. A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2025-31281P3CRITICALCVSS 9.1fixed in 18.62025-07-30
CVE-2025-31281 [CRITICAL] CWE-20 CVE-2025-31281: An input validation issue was addressed with improved memory handling. This issue is fixed in iOS 18 An input validation issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6. Processing a maliciously crafted file may lead to unexpected app termination.
nvd
CVE-2025-30448P3CRITICALCVSS 9.1fixed in 18.52025-05-12
CVE-2025-30448 [CRITICAL] CWE-862 CVE-2025-30448: This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.5 and iPa This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, visionOS 2.5. An attacker may be able to turn on sharing of an iCloud folder without authentication.
nvd
CVE-2021-30939P3HIGHCVSS 7.8≥ unspecified, < 15.22021-08-24
CVE-2021-30939 [HIGH] CWE-125 CVE-2021-30939: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2024-54525P3HIGHCVSS 8.8fixed in 18.22025-03-17
CVE-2024-54525 [HIGH] CWE-434 CVE-2024-54525: A logic issue was addressed with improved file handling. This issue is fixed in iOS 18.2 and iPadOS A logic issue was addressed with improved file handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Restoring a maliciously crafted backup file may lead to modification of protected system files.
nvd
Apple Ios And Ipados vulnerabilities | cvebase