Apple Ios And Ipados vulnerabilities
1,534 known vulnerabilities affecting apple/ios_and_ipados.
Total CVEs
1,534
CISA KEV
57
actively exploited
Public exploits
1
Exploited in wild
44
Severity breakdown
CRITICAL73HIGH605MEDIUM736LOW120
Vulnerabilities
Page 23 of 77
CVE-2025-24208MEDIUMCVSS 6.1fixed in 18.42025-03-31
CVE-2025-24208 [MEDIUM] CWE-79 CVE-2025-24208: A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 18.4,
A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4. Loading a malicious iframe may lead to a cross-site scripting attack.
nvd
CVE-2025-24194MEDIUMCVSS 6.5fixed in 18.42025-03-31
CVE-2025-24194 [MEDIUM] CVE-2025-24194: A logic issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, m
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may result in the disclosure of process memory.
nvd
CVE-2025-31192MEDIUMCVSS 6.7fixed in 18.42025-03-31
CVE-2025-31192 [MEDIUM] CWE-305 CVE-2025-31192: The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadO
The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A website may be able to access sensor information without user consent.
nvd
CVE-2025-30428MEDIUMCVSS 5.4fixed in 18.42025-03-31
CVE-2025-30428 [MEDIUM] CWE-305 CVE-2025-30428: This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPad
This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6. Photos in the Hidden Photos Album may be viewed without authentication.
nvd
CVE-2025-30467MEDIUMCVSS 4.3fixed in 18.42025-03-31
CVE-2025-30467 [MEDIUM] CWE-451 CVE-2025-30467: The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadO
The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, watchOS 11.4. Visiting a malicious website may lead to address bar spoofing.
nvd
CVE-2025-30454MEDIUMCVSS 5.5fixed in 18.42025-03-31
CVE-2025-30454 [MEDIUM] CWE-200 CVE-2025-30454: A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.4 and iP
A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, tvOS 18.4, watchOS 11.4. A malicious app may be able to access private information.
nvd
CVE-2025-24198MEDIUMCVSS 6.6fixed in 18.42025-03-31
CVE-2025-24198 [MEDIUM] CWE-284 CVE-2025-24198: This issue was addressed by restricting options offered on a locked device. This issue is fixed in i
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker with physical access may be able to use Siri to access sensitive user data.
nvd
CVE-2025-24212MEDIUMCVSS 6.3fixed in 18.42025-03-31
CVE-2025-24212 [MEDIUM] CVE-2025-24212: This issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPad
This issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to break out of its sandbox.
nvd
CVE-2025-30447MEDIUMCVSS 5.5fixed in 18.42025-03-31
CVE-2025-30447 [MEDIUM] CWE-200 CVE-2025-30447: The issue was resolved by sanitizing logging. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadO
The issue was resolved by sanitizing logging. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to access sensitive user data.
nvd
CVE-2025-30439MEDIUMCVSS 4.6fixed in 18.42025-03-31
CVE-2025-30439 [MEDIUM] CWE-200 CVE-2025-30439: The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS
The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. An attacker with physical access to a locked device may be able to view sensitive user information.
nvd
CVE-2025-30469LOWCVSS 2.4fixed in 18.42025-03-31
CVE-2025-30469 [LOW] CWE-863 CVE-2025-30469: This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPad
This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4. A person with physical access to an iOS device may be able to access photos from the lock screen.
nvd
CVE-2024-40864LOWCVSS 2.7fixed in 18.22025-03-31
CVE-2024-40864 [LOW] CWE-200 CVE-2024-40864: The issue was addressed with improved handling of protocols. This issue is fixed in iOS 18.2 and iPa
The issue was addressed with improved handling of protocols. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.2, watchOS 11.2. An attacker in a privileged network position may be able to track a user's activity.
nvd
CVE-2025-24193LOWCVSS 2.4fixed in 18.42025-03-31
CVE-2025-24193 [LOW] CWE-284 CVE-2025-24193: This issue was addressed with improved authentication. This issue is fixed in iOS 18.4 and iPadOS 18
This issue was addressed with improved authentication. This issue is fixed in iOS 18.4 and iPadOS 18.4. An attacker with a USB-C connection to an unlocked device may be able to programmatically access photos.
nvd
CVE-2024-54551HIGHCVSS 7.5fixed in 17.62025-03-21
CVE-2024-54551 [HIGH] CWE-119 CVE-2024-54551: The issue was addressed with improved memory handling. This issue is fixed in Safari 17.6, iOS 17.6
The issue was addressed with improved memory handling. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing web content may lead to a denial-of-service.
nvd
CVE-2024-54564MEDIUMCVSS 6.5fixed in 17.62025-03-21
CVE-2024-54564 [MEDIUM] CWE-276 CVE-2024-54564: This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPad
This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, visionOS 1.3. A file received from AirDrop may not have the quarantine flag applied.
nvd
CVE-2024-54525HIGHCVSS 8.8fixed in 18.22025-03-17
CVE-2024-54525 [HIGH] CWE-434 CVE-2024-54525: A logic issue was addressed with improved file handling. This issue is fixed in iOS 18.2 and iPadOS
A logic issue was addressed with improved file handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Restoring a maliciously crafted backup file may lead to modification of protected system files.
nvd
CVE-2024-44276HIGHCVSS 7.3fixed in 18.22025-03-17
CVE-2024-44276 [HIGH] CWE-319 CVE-2024-44276: This issue was addressed by using HTTPS when sending information over the network. This issue is fix
This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.2 and iPadOS 18.2. A user in a privileged network position may be able to leak sensitive information.
nvd
CVE-2025-24201CRITICALCVSS 10.0KEVfixed in 15.8.4fixed in 16.7.11+1 more2025-03-11
CVE-2025-24201 [CRITICAL] CWE-787 CVE-2025-24201: An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. Thi
An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.2 and iPadOS 18.3.2, iPadOS 17.7.6, macOS Sequoia 15.3.2, visionOS 2.3.2, watchOS 11.4. Maliciously crafted web content may be able to break ou
nvd
CVE-2022-43454HIGHCVSS 7.8≥ unspecified, < 16.22025-03-10
CVE-2022-43454 [HIGH] CWE-415 CVE-2022-43454: A double free issue was addressed with improved memory management. This issue is fixed in macOS Vent
A double free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2024-44227HIGHCVSS 7.5fixed in 182025-03-10
CVE-2024-44227 [HIGH] CWE-400 CVE-2024-44227: The issue was addressed with improved memory handling. This issue is fixed in iOS 18 and iPadOS 18,
The issue was addressed with improved memory handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to cause unexpected system termination or corrupt kernel memory.
nvd