cbcvebase.

Apple Ios And Ipados vulnerabilities

1,656 known vulnerabilities affecting apple/ios_and_ipados.

Total CVEs
1,656
CISA KEV
57
actively exploited
Public exploits
17
Exploited in wild
72
Severity breakdown
CRITICAL74HIGH615MEDIUM765LOW120UNKNOWN82

Vulnerabilities

Page 3 of 83
CVE-2022-48618P1HIGHCVSS 7.0KEV≥ unspecified, < 16.22024-01-09
CVE-2022-48618 [HIGH] CWE-367 CVE-2022-48618: The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2 The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited against versions of iOS released before iOS 15.7
nvd
CVE-2023-41061P1HIGHCVSS 7.8KEV≥ unspecified, < 16.62023-09-07
CVE-2023-41061 [HIGH] CWE-20 CVE-2023-41061: A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6 A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted attachment may result in arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
nvd
CVE-2023-41992P1HIGHCVSS 7.8KEV≥ unspecified, < 16.72023-09-21
CVE-2023-41992 [HIGH] CWE-754 CVE-2023-41992: The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 a The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macOS Ventura 13.6. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
nvd
CVE-2024-23225P1HIGHCVSS 7.8KEVfixed in 16.7.6fixed in 17.42024-03-05
CVE-2024-23225 [HIGH] CWE-787 CVE-2024-23225: A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protection
nvd
CVE-2024-23296P1HIGHCVSS 7.8KEVfixed in 16.7.8fixed in 17.42024-03-05
CVE-2024-23296 [HIGH] CWE-787 CVE-2024-23296: A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.7, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protection
nvd
CVE-2022-42827P1HIGHCVSS 7.8KEV≥ unspecified, < 16.1≥ unspecified, < 15.72022-11-01
CVE-2022-42827 [HIGH] CWE-787 CVE-2022-42827: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..
nvd
CVE-2024-44309P1MEDIUMCVSS 6.3KEVfixed in 17.7.2fixed in 18.1.12024-11-20
CVE-2024-44309 [MEDIUM] CWE-79 CVE-2024-44309: A cookie management issue was addressed with improved state management. This issue is fixed in Safar A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to a cross site scripting attack. Apple is aware of a report that this issue may have been a
nvd
CVE-2021-30869P1HIGHCVSS 7.8KEV≥ unspecified, < 14.42021-08-24
CVE-2021-30869 [HIGH] CWE-843 CVE-2021-30869: A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 12.5.5 A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 12.5.5, iOS 14.4 and iPadOS 14.4, macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, Security Update 2021-006 Catalina. A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware o
nvd
CVE-2023-42916P1MEDIUMCVSS 6.5KEV≥ unspecified, < 17.12023-11-30
CVE-2023-42916 [MEDIUM] CWE-125 CVE-2023-42916: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1. An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.
nvd
CVE-2023-28204P1MEDIUMCVSS 6.5KEV≥ unspecified, < 15.7≥ unspecified, < 16.52023-06-23
CVE-2023-28204 [MEDIUM] CWE-125 CVE-2023-28204: An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9 An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been actively exploited.
nvd
CVE-2023-38606P1MEDIUMCVSS 5.5KEV≥ unspecified, < 16.6≥ unspecified, < 15.72023-07-27
CVE-2023-38606 [MEDIUM] CVE-2023-38606: This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6. This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to modify sensitive kernel state. Apple is aware of a report that this issue may have been actively exploited again
nvd
CVE-2025-43510P1HIGHCVSS 7.8KEVfixed in 18.7.2fixed in 26.12025-12-12
CVE-2025-43510 [HIGH] CWE-667 CVE-2025-43510: A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iO A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may cause unexpected changes in memory shared between processes.
nvd
CVE-2021-1879P1MEDIUMCVSS 6.1KEV≥ unspecified, < 14.42021-04-02
CVE-2021-1879 [MEDIUM] CWE-79 CVE-2021-1879: This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5 This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and iPadOS 14.4.2, watchOS 7.3.3. Processing maliciously crafted web content may lead to universal cross site scripting. Apple is aware of a report that this issue may have been actively exploited..
nvd
CVE-2025-43520P1MEDIUMCVSS 5.5KEVfixed in 18.7.2fixed in 26.12025-12-12
CVE-2025-43520 [MEDIUM] CWE-120 CVE-2025-43520: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18 A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2025-24200P2MEDIUMCVSS 6.1KEVfixed in 15.8.4fixed in 16.7.11+1 more2025-02-10
CVE-2025-24200 [MEDIUM] CWE-863 CVE-2025-24200: An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8 An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5. A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may have been exploited in an extremely
nvd
CVE-2025-43200P2MEDIUMCVSS 4.2KEVfixed in 15.8.4fixed in 16.7.11+1 more2025-06-16
CVE-2025-43200 [MEDIUM] CVE-2025-43200: This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.7.4, visionOS 2.3.1, watchOS 11.3.1. A logic issue existed when processing a maliciously crafted photo or video shared via
nvd
CVE-2021-30983P2HIGHCVSS 7.8KEV≥ unspecified, < 15.22021-08-24
CVE-2021-30983 [HIGH] CWE-120 CVE-2021-30983: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 15.2 A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 15.2 and iPadOS 15.2. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2024-44258P1HIGHCVSS 7.1ExploitedPoCfixed in 17.7.1fixed in 18.12024-10-28
CVE-2024-44258 [HIGH] CWE-59 CVE-2024-44258: This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 17.7.1 and i This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, tvOS 18.1, visionOS 2.1. Restoring a maliciously crafted backup file may lead to modification of protected system files.
nvd
CVE-2023-23496P1HIGHCVSS 8.8Exploited≥ unspecified, < 16.3≥ unspecified, < 15.72023-02-27
CVE-2023-23496 [HIGH] CWE-94 CVE-2023-23496: The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.2, watchOS 9.3 The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.2, watchOS 9.3, iOS 15.7.2 and iPadOS 15.7.2, Safari 16.3, tvOS 16.3, iOS 16.3 and iPadOS 16.3. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2021-30737P1HIGHCVSS 8.8Exploited≥ unspecified, < 14.62021-09-08
CVE-2021-30737 [HIGH] CWE-787 CVE-2021-30737: A memory corruption issue in the ASN.1 decoder was addressed by removing the vulnerable code. This i A memory corruption issue in the ASN.1 decoder was addressed by removing the vulnerable code. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, iOS 12.5.4, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. Processing a maliciously crafted certificate may lead to arbitrary code execution.
nvd
Apple Ios And Ipados vulnerabilities | cvebase