cbcvebase.

Apple Ios And Ipados vulnerabilities

1,703 known vulnerabilities affecting apple/ios_and_ipados.

Total CVEs
1,703
CISA KEV
57
actively exploited
Public exploits
17
Exploited in wild
72
Severity breakdown
CRITICAL106HIGH646MEDIUM828LOW123

Vulnerabilities

Page 36 of 86
CVE-2025-24173P3HIGHCVSS 7.8fixed in 18.42025-03-31
CVE-2025-24173 [HIGH] CWE-284 CVE-2025-24173: This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPa This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to break out of its sandbox.
nvd
CVE-2024-44225P3HIGHCVSS 7.8fixed in 18.22024-12-12
CVE-2024-44225 [HIGH] CVE-2024-44225: A logic issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, i A logic issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, watchOS 11.2. An app may be able to gain elevated privileges.
nvd
CVE-2024-44218P3HIGHCVSS 7.8fixed in 17.7.1fixed in 18.12024-10-28
CVE-2024-44218 [HIGH] CWE-787 CVE-2024-44218: This issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, This issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1. Processing a maliciously crafted file may lead to heap corruption.
nvd
CVE-2023-40419P3HIGHCVSS 7.8≥ unspecified, < 172023-09-27
CVE-2023-40419 [HIGH] CVE-2023-40419: The issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, The issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10. An app may be able to gain elevated privileges.
nvd
CVE-2025-31184P3HIGHCVSS 7.8fixed in 18.42025-03-31
CVE-2025-31184 [HIGH] CWE-281 CVE-2025-31184: This issue was addressed with improved permissions checking. This issue is fixed in Safari 18.4, iOS This issue was addressed with improved permissions checking. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4. An app may gain unauthorized access to Local Network.
nvd
CVE-2021-1787P3HIGHCVSS 7.8≥ unspecified, < 14.42021-04-02
CVE-2021-1787 [HIGH] CWE-269 CVE-2021-1787: Multiple issues were addressed with improved logic. This issue is fixed in macOS Big Sur 11.2, Secur Multiple issues were addressed with improved logic. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A local attacker may be able to elevate their privileges.
nvd
CVE-2021-30882P3HIGHCVSS 7.5≥ unspecified, < 152021-08-24
CVE-2021-30882 [HIGH] CVE-2021-30882: A logic issue was addressed with improved validation. This issue is fixed in watchOS 8, iOS 15 and i A logic issue was addressed with improved validation. This issue is fixed in watchOS 8, iOS 15 and iPadOS 15. An application with microphone permission may unexpectedly access microphone input during a FaceTime call.
nvd
CVE-2024-27848P3HIGHCVSS 7.8fixed in 17.52024-06-10
CVE-2024-27848 [HIGH] CWE-863 CVE-2024-27848: This issue was addressed with improved permissions checking. This issue is fixed in iOS 17.5 and iPa This issue was addressed with improved permissions checking. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. A malicious app may be able to gain root privileges.
nvd
CVE-2023-32359P3HIGHCVSS 7.5≥ unspecified, < 16.72023-10-25
CVE-2023-32359 [HIGH] CVE-2023-32359: This issue was addressed with improved redaction of sensitive information. This issue is fixed in iO This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2. A user's password may be read aloud by VoiceOver.
nvd
CVE-2021-31005P3HIGHCVSS 7.5≥ unspecified, < 152021-08-24
CVE-2021-31005 [HIGH] CVE-2021-31005: Description: A logic issue was addressed with improved state management. This issue is fixed in iOS Description: A logic issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15, macOS Monterey 12.0.1. Turning off "Block all remote content" may not apply to all remote content types.
nvd
CVE-2025-24177P3HIGHCVSS 7.5fixed in 18.32025-01-27
CVE-2025-24177 [HIGH] CWE-476 CVE-2025-24177: A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker on the local network may be able to cause a denial-of-service.
nvd
CVE-2024-27879P3HIGHCVSS 7.5fixed in 17.7fixed in 182024-09-17
CVE-2024-27879 [HIGH] CWE-119 CVE-2024-27879: The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7 and iPadOS 17.7 The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18. An attacker may be able to cause unexpected app termination.
nvd
CVE-2023-42962P3HIGHCVSS 7.5≥ unspecified, < 17.2≥ unspecified, < 16.72024-03-28
CVE-2023-42962 [HIGH] CVE-2023-42962: This issue was addressed with improved checks This issue is fixed in iOS 17.2 and iPadOS 17.2, iOS 1 This issue was addressed with improved checks This issue is fixed in iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3. A remote attacker may be able to cause a denial-of-service.
nvd
CVE-2023-42869P3HIGHCVSS 7.5≥ unspecified, < 16.52024-01-10
CVE-2023-42869 [HIGH] CWE-787 CVE-2023-42869: Multiple memory corruption issues were addressed with improved input validation. This issue is fixed Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Ventura 13.4, iOS 16.5 and iPadOS 16.5. Multiple issues in libxml2.
nvd
CVE-2026-43725P3HIGHCVSS 7.1fixed in 18.7.10fixed in 26.5.22026-06-29
CVE-2026-43725 [HIGH] CWE-20 CVE-2026-43725: The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 18 The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to process restricted web content outside the sandbox.
nvd
CVE-2024-54486P3MEDIUMCVSS 6.5fixed in 18.22024-12-12
CVE-2024-54486 [MEDIUM] CVE-2024-54486: The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadO The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing a maliciously crafted font may result in the disclosure of process memory.
nvd
CVE-2023-28182P3MEDIUMCVSS 6.5≥ unspecified, < 16.4≥ unspecified, < 15.72023-05-08
CVE-2023-28182 [MEDIUM] CWE-287 CVE-2023-28182: The issue was addressed with improved authentication. This issue is fixed in macOS Ventura 13.3, iOS The issue was addressed with improved authentication. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A user in a privileged network position may be able to spoof a VPN server that is configured with EAP-only authentication on a device.
nvd
CVE-2025-31233P3MEDIUMCVSS 6.3fixed in 18.52025-05-12
CVE-2025-31233 [MEDIUM] CWE-20 CVE-2025-31233: The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.5 and iPadOS The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory.
nvd
CVE-2025-30432P3MEDIUMCVSS 6.4fixed in 18.42025-03-31
CVE-2025-30432 [MEDIUM] CWE-287 CVE-2025-30432: A logic issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPad A logic issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. A malicious app may be able to attempt passcode entries on a locked device and thereby cause escalating time delays after 4 failures.
nvd
CVE-2025-31209P3MEDIUMCVSS 6.3fixed in 18.52025-05-12
CVE-2025-31209 [MEDIUM] CWE-125 CVE-2025-31209: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 a An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. Parsing a file may lead to disclosure of user information.
nvd
Apple Ios And Ipados vulnerabilities | cvebase