Apple Ios And Ipados vulnerabilities
1,703 known vulnerabilities affecting apple/ios_and_ipados.
Total CVEs
1,703
CISA KEV
57
actively exploited
Public exploits
17
Exploited in wild
72
Severity breakdown
CRITICAL106HIGH646MEDIUM828LOW123
Vulnerabilities
Page 38 of 86
CVE-2021-30888P3HIGHCVSS 7.4≥ unspecified, < 15.1≥ unspecified, < 14.82021-08-24
CVE-2021-30888 [HIGH] CWE-601 CVE-2021-30888: An information leakage issue was addressed. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS M
An information leakage issue was addressed. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvOS 15.1, watchOS 8.1. A malicious website using Content Security Policy reports may be able to leak information via redirect behavior .
nvd
CVE-2021-30729P3HIGHCVSS 7.5≥ unspecified, < 14.62021-09-08
CVE-2021-30729 [HIGH] CVE-2021-30729: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 14.6 and iPadOS 1
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 14.6 and iPadOS 14.6. A device may accept invalid activation results.
nvd
CVE-2023-40443P3HIGHCVSS 7.8≥ unspecified, < 172023-09-27
CVE-2023-40443 [HIGH] CVE-2023-40443: The issue was addressed with improved checks. This issue is fixed in iOS 17 and iPadOS 17. An app ma
The issue was addressed with improved checks. This issue is fixed in iOS 17 and iPadOS 17. An app may be able to gain root privileges.
nvd
CVE-2022-22673P3HIGHCVSS 7.5≥ unspecified, < 15.52022-05-26
CVE-2022-22673 [HIGH] CVE-2022-22673: This issue was addressed with improved checks. This issue is fixed in iOS 15.5 and iPadOS 15.5. Proc
This issue was addressed with improved checks. This issue is fixed in iOS 15.5 and iPadOS 15.5. Processing a large input may lead to a denial of service.
nvd
CVE-2023-42977P3HIGHCVSS 7.8≥ unspecified, < 172025-04-11
CVE-2023-42977 [HIGH] CWE-20 CVE-2023-42977: A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPad
A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to break out of its sandbox.
nvd
CVE-2023-42928P3HIGHCVSS 7.8≥ unspecified, < 17.12024-02-21
CVE-2023-42928 [HIGH] CWE-276 CVE-2023-42928: The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.1 and iPadOS 17.1
The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.1 and iPadOS 17.1. An app may be able to gain elevated privileges.
nvd
CVE-2025-31207P3HIGHCVSS 7.7fixed in 18.52025-05-12
CVE-2025-31207 [HIGH] CWE-200 CVE-2025-31207: A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. A
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. An app may be able to enumerate a user's installed apps.
nvd
CVE-2026-28950P3MEDIUMCVSS 6.2fixed in 15.8.8fixed in 16.7.16+2 more2026-04-22
CVE-2026-28950 [MEDIUM] CWE-359 CVE-2026-28950: A logging issue was addressed with improved data redaction. This issue is fixed in iOS 15.8.8 and iP
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 15.8.8 and iPadOS 15.8.8, iOS 16.7.16 and iPadOS 16.7.16, iOS 18.7.8 and iPadOS 18.7.8, iOS 26.4.2 and iPadOS 26.4.2, iPadOS 17.7.11. Notifications marked for deletion could be unexpectedly retained on the device.
nvd
CVE-2021-1799P3MEDIUMCVSS 6.5≥ unspecified, < 14.42021-04-02
CVE-2021-1799 [MEDIUM] CVE-2021-1799: A port redirection issue was addressed with additional port validation. This issue is fixed in macOS
A port redirection issue was addressed with additional port validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. A malicious website may be able to access restricted ports on arbitrary servers.
nvd
CVE-2024-23263P3MEDIUMCVSS 6.5fixed in 16.7.6fixed in 17.42024-03-08
CVE-2024-23263 [MEDIUM] CWE-20 CVE-2024-23263: A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6
A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
nvd
CVE-2024-23284P3MEDIUMCVSS 6.5fixed in 16.7.6fixed in 17.42024-03-08
CVE-2024-23284 [MEDIUM] CWE-693 CVE-2024-23284: A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS
A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
nvd
CVE-2026-28878P3MEDIUMCVSS 6.5fixed in 18.7.7fixed in 26.42026-03-25
CVE-2026-28878 [MEDIUM] CWE-200 CVE-2026-28878: A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.7.7 and iPad
A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.7, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to enumerate a user's installed apps.
nvd
CVE-2025-43210P3MEDIUMCVSS 6.3fixed in 18.62026-04-02
CVE-2025-43210 [MEDIUM] CWE-125 CVE-2025-43210: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
nvd
CVE-2026-43701P4HIGHCVSS 7.1fixed in 18.7.10fixed in 26.5.22026-06-29
CVE-2026-43701 [HIGH] CWE-284 CVE-2026-43701: The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and
The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to process restricted web content outside the sandbox.
nvd
CVE-2025-31225P4HIGHCVSS 7.1fixed in 18.52025-05-12
CVE-2025-31225 [HIGH] CWE-200 CVE-2025-31225: A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.5 and iPadOS
A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.5 and iPadOS 18.5. Call history from deleted apps may still appear in spotlight search results.
nvd
CVE-2026-20617P4HIGHCVSS 7.0fixed in 26.32026-02-11
CVE-2026-20617 [HIGH] CWE-362 CVE-2026-20617: A race condition was addressed with improved state handling. This issue is fixed in iOS 26.3 and iPa
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to gain root privileges.
nvd
CVE-2023-40416P4MEDIUMCVSS 6.5≥ unspecified, < 16.7≥ unspecified, < 17.12023-10-25
CVE-2023-40416 [MEDIUM] CWE-119 CVE-2023-40416: The issue was addressed with improved memory handling. This issue is fixed in iOS 17.1 and iPadOS 17
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.1 and iPadOS 17.1, macOS Monterey 12.7.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Ventura 13.6.1, macOS Sonoma 14.1. Processing an image may result in disclosure of process memory.
nvd
CVE-2026-28880P4MEDIUMCVSS 6.5fixed in 18.7.7fixed in 26.42026-03-25
CVE-2026-28880 [MEDIUM] CWE-284 CVE-2026-28880: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.7 an
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4. An app may be able to enumerate a user's installed apps.
nvd
CVE-2026-43707P4MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-43707 [MEDIUM] CWE-119 CVE-2026-43707: A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari
A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2025-46287P4MEDIUMCVSS 6.5fixed in 18.7.3fixed in 26.22025-12-12
CVE-2025-46287 [MEDIUM] CWE-451 CVE-2025-46287: An inconsistent user interface issue was addressed with improved state management. This issue is fix
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2. An attacker may be able to spoof their FaceTime caller ID.
nvd