Apple Ios And Ipados vulnerabilities

1,463 known vulnerabilities affecting apple/ios_and_ipados.

Total CVEs
1,463
CISA KEV
57
actively exploited
Public exploits
1
Exploited in wild
44
Severity breakdown
CRITICAL73HIGH563MEDIUM708LOW119

Vulnerabilities

Page 32 of 74
CVE-2024-27840MEDIUMCVSS 6.3fixed in 16.7.8fixed in 17.52024-06-10
CVE-2024-27840 [MEDIUM] CWE-786 CVE-2024-27840: The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.2, watchOS 10.5. An attacker that has already achieved kernel code execution may be able to bypass kernel memory protections.
nvd
CVE-2024-27830MEDIUMCVSS 6.5fixed in 17.52024-06-10
CVE-2024-27830 [MEDIUM] CVE-2024-27830: This issue was addressed through improved state management. This issue is fixed in Safari 17.5, iOS This issue was addressed through improved state management. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. A maliciously crafted webpage may be able to fingerprint the user.
nvd
CVE-2024-27805MEDIUMCVSS 5.5fixed in 16.7.8fixed in 17.52024-06-10
CVE-2024-27805 [MEDIUM] CWE-20 CVE-2024-27805: An issue was addressed with improved validation of environment variables. This issue is fixed in iOS An issue was addressed with improved validation of environment variables. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, watchOS 10.5. An app may be able to access sensitive user data.
nvd
CVE-2024-23251MEDIUMCVSS 4.6fixed in 16.7.8fixed in 17.52024-06-10
CVE-2024-23251 [MEDIUM] CWE-287 CVE-2024-23251: An authentication issue was addressed with improved state management. This issue is fixed in iOS 16. An authentication issue was addressed with improved state management. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, watchOS 10.5. An attacker with physical access may be able to leak Mail account credentials.
nvd
CVE-2024-27800MEDIUMCVSS 6.5fixed in 16.7.8fixed in 17.52024-06-10
CVE-2024-27800 [MEDIUM] CWE-400 CVE-2024-27800: This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.8 and iPad This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing a maliciously crafted message may lead to a denial-of-service.
nvd
CVE-2024-27838MEDIUMCVSS 6.5fixed in 16.7.8fixed in 17.52024-06-10
CVE-2024-27838 [MEDIUM] CWE-79 CVE-2024-27838: The issue was addressed by adding additional logic. This issue is fixed in Safari 17.5, iOS 16.7.8 a The issue was addressed by adding additional logic. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. A maliciously crafted webpage may be able to fingerprint the user.
nvd
CVE-2024-27806MEDIUMCVSS 5.5fixed in 16.7.8fixed in 17.52024-06-10
CVE-2024-27806 [MEDIUM] CWE-200 CVE-2024-27806: This issue was addressed with improved environment sanitization. This issue is fixed in iOS 16.7.8 a This issue was addressed with improved environment sanitization. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, watchOS 10.5. An app may be able to access sensitive user data.
nvd
CVE-2024-27799LOWCVSS 3.3fixed in 16.7.82024-06-10
CVE-2024-27799 [LOW] CVE-2024-27799: This issue was addressed with additional entitlement checks. This issue is fixed in iOS 16.7.8 and i This issue was addressed with additional entitlement checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7. An unprivileged app may be able to log keystrokes in other apps including those using secure input mode.
nvd
CVE-2024-27845LOWCVSS 3.3fixed in 17.52024-06-10
CVE-2024-27845 [LOW] CVE-2024-27845: A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.5 and iPadOS 17.5. An app may be able to access Notes attachments.
nvd
CVE-2024-27819LOWCVSS 2.4fixed in 17.52024-06-10
CVE-2024-27819 [LOW] CWE-284 CVE-2024-27819: The issue was addressed by restricting options offered on a locked device. This issue is fixed in iO The issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access may be able to access contacts from the lock screen.
nvd
CVE-2024-27796HIGHCVSS 7.8fixed in 16.7.8fixed in 17.52024-05-14
CVE-2024-27796 [HIGH] CWE-1325 CVE-2024-27796: The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, i The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7. An attacker may be able to elevate privileges.
nvd
CVE-2024-27818HIGHCVSS 7.8fixed in 16.7.8fixed in 17.52024-05-14
CVE-2024-27818 [HIGH] CWE-77 CVE-2024-27818: The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An attacker may be able to cause unexpected app termination or arbitrary code execution.
nvd
CVE-2024-27816MEDIUMCVSS 5.5fixed in 17.52024-05-14
CVE-2024-27816 [MEDIUM] CVE-2024-27816: A logic issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, m A logic issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, watchOS 10.5. An attacker may be able to access user data.
nvd
CVE-2024-27847MEDIUMCVSS 5.5fixed in 16.7.8fixed in 17.52024-05-14
CVE-2024-27847 [MEDIUM] CWE-277 CVE-2024-27847: This issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, This issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7. An app may be able to bypass Privacy preferences.
nvd
CVE-2024-27852MEDIUMCVSS 6.5fixed in 17.52024-05-14
CVE-2024-27852 [MEDIUM] CVE-2024-27852: A privacy issue was addressed with improved client ID handling for alternative app marketplaces. Thi A privacy issue was addressed with improved client ID handling for alternative app marketplaces. This issue is fixed in iOS 17.5 and iPadOS 17.5. A maliciously crafted webpage may be able to distribute a script that tracks users on other webpages.
nvd
CVE-2024-27821MEDIUMCVSS 4.7fixed in 17.52024-05-14
CVE-2024-27821 [MEDIUM] CWE-22 CVE-2024-27821: A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iP A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, watchOS 10.5. A shortcut may output sensitive user data without consent.
nvd
CVE-2024-27810MEDIUMCVSS 5.5fixed in 17.52024-05-14
CVE-2024-27810 [MEDIUM] CWE-22 CVE-2024-27810: A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iP A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, watchOS 10.5. An app may be able to read sensitive location information.
nvd
CVE-2024-27841MEDIUMCVSS 5.5fixed in 17.52024-05-14
CVE-2024-27841 [MEDIUM] CWE-284 CVE-2024-27841: The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17 The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An app may be able to disclose kernel memory.
nvd
CVE-2024-27804MEDIUMCVSS 5.5fixed in 17.52024-05-14
CVE-2024-27804 [MEDIUM] CWE-770 CVE-2024-27804: The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17 The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.3, watchOS 10.5. An app may be able to cause unexpected system termination.
nvd
CVE-2024-27834MEDIUMCVSS 5.5fixed in 16.7.8fixed in 17.52024-05-14
CVE-2024-27834 [MEDIUM] CWE-277 CVE-2024-27834: The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPa The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, watchOS 10.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
nvd