Apple Ios And Ipados vulnerabilities
1,703 known vulnerabilities affecting apple/ios_and_ipados.
Total CVEs
1,703
CISA KEV
57
actively exploited
Public exploits
17
Exploited in wild
72
Severity breakdown
CRITICAL106HIGH646MEDIUM828LOW123
Vulnerabilities
Page 23 of 86
CVE-2023-23536P3HIGHCVSS 7.8≥ unspecified, < 16.4≥ unspecified, < 15.72023-05-08
CVE-2023-23536 [HIGH] CVE-2023-23536: The issue was addressed with improved bounds checks. This issue is fixed in macOS Ventura 13.3, iOS
The issue was addressed with improved bounds checks. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, macOS Big Sur 11.7.5, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, tvOS 16.4, watchOS 9.4. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2024-23270P3HIGHCVSS 7.8fixed in 17.42024-03-08
CVE-2024-23270 [HIGH] CWE-787 CVE-2024-23270: The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2024-27826P3HIGHCVSS 7.8fixed in 17.52024-07-29
CVE-2024-27826 [HIGH] CWE-269 CVE-2024-27826: The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.6, macOS Sonoma 14.5, macOS Ventura 13.6.8, tvOS 17.5, visionOS 1.3, watchOS 10.5. A local attacker may be able to cause unexpected system shutdown.
nvd
CVE-2023-28181P3HIGHCVSS 7.8≥ unspecified, < 16.4≥ unspecified, < 15.72023-05-08
CVE-2023-28181 [HIGH] CVE-2023-28181: The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, iO
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.6 and iPadOS 15.7.6, macOS Monterey 12.6.4, macOS Big Sur 11.7.7, tvOS 16.4, watchOS 9.4. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2023-32398P3HIGHCVSS 7.8≥ unspecified, < 15.7≥ unspecified, < 16.52023-06-23
CVE-2023-32398 [HIGH] CWE-416 CVE-2023-32398: A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS
A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2025-31222P3HIGHCVSS 7.8fixed in 18.52025-05-12
CVE-2025-31222 [HIGH] CWE-269 CVE-2025-31222: A correctness issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 1
A correctness issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. A user may be able to elevate privileges.
nvd
CVE-2023-32441P3HIGHCVSS 7.8≥ unspecified, < 16.6≥ unspecified, < 15.72023-07-27
CVE-2023-32441 [HIGH] CVE-2023-32441: The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.8,
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2025-24107P3HIGHCVSS 7.8fixed in 18.32025-01-27
CVE-2025-24107 [HIGH] CWE-276 CVE-2025-24107: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, watchOS 11.3. A malicious app may be able to gain root privileges.
nvd
CVE-2022-43454P3HIGHCVSS 7.8≥ unspecified, < 16.22025-03-10
CVE-2022-43454 [HIGH] CWE-415 CVE-2022-43454: A double free issue was addressed with improved memory management. This issue is fixed in macOS Vent
A double free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2023-41075P3HIGHCVSS 7.8≥ unspecified, < 16.4≥ unspecified, < 15.72024-01-10
CVE-2023-41075 [HIGH] CWE-843 CVE-2023-41075: A type confusion issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.7
A type confusion issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.7.5, macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2024-27817P3HIGHCVSS 7.8fixed in 16.7.8fixed in 17.52024-06-10
CVE-2024-27817 [HIGH] CWE-353 CVE-2024-27817: The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, i
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.2. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2025-46290P3HIGHCVSS 7.5fixed in 18.7.3fixed in 26.22026-02-11
CVE-2025-46290 [HIGH] CWE-693 CVE-2025-46290: A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2. A remote attacker may be able to cause a denial-of-service.
nvd
CVE-2026-28951P3HIGHCVSS 7.8fixed in 18.7.9fixed in 26.52026-05-11
CVE-2026-28951 [HIGH] CWE-863 CVE-2026-28951: An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to gain root privileges.
nvd
CVE-2026-20626P3HIGHCVSS 7.8fixed in 26.32026-02-11
CVE-2026-20626 [HIGH] CWE-862 CVE-2026-20626: This issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macO
This issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Tahoe 26.3, visionOS 26.3. A malicious app may be able to gain root privileges.
nvd
CVE-2025-24221P3HIGHCVSS 7.5fixed in 18.42025-03-31
CVE-2025-24221 [HIGH] CWE-863 CVE-2025-24221: This issue was addressed with improved data access restriction. This issue is fixed in iOS 18.4 and
This issue was addressed with improved data access restriction. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, visionOS 2.4. Sensitive keychain data may be accessible from an iOS backup.
nvd
CVE-2026-28865P3HIGHCVSS 7.5fixed in 18.7.7fixed in 26.42026-03-25
CVE-2026-28865 [HIGH] CWE-285 CVE-2026-28865: An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.
An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An attacker in a privileged network position may be able to intercept network traffic.
nvd
CVE-2026-28959P3HIGHCVSS 7.5fixed in 18.7.9fixed in 26.52026-05-11
CVE-2026-28959 [HIGH] CWE-120 CVE-2026-28959: A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination.
nvd
CVE-2025-43399P3HIGHCVSS 7.5fixed in 18.7.22025-11-04
CVE-2025-43399 [HIGH] CWE-359 CVE-2025-43399: This issue was addressed with improved redaction of sensitive information. This issue is fixed in iO
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, macOS Sequoia 15.7.2, macOS Tahoe 26.1. An app may be able to access protected user data.
nvd
CVE-2026-28969P3HIGHCVSS 7.5fixed in 18.7.9fixed in 26.52026-05-11
CVE-2026-28969 [HIGH] CWE-416 CVE-2026-28969: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination.
nvd
CVE-2026-28906P3HIGHCVSS 7.5fixed in 18.7.9fixed in 26.52026-05-11
CVE-2026-28906 [HIGH] CWE-359 CVE-2026-28906: This issue was addressed through improved state management. This issue is fixed in iOS 18.7.9 and iP
This issue was addressed through improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, visionOS 26.5. An attacker may be able to track users through their IP address.
nvd