Apple Ios And Ipados vulnerabilities
1,703 known vulnerabilities affecting apple/ios_and_ipados.
Total CVEs
1,703
CISA KEV
57
actively exploited
Public exploits
17
Exploited in wild
72
Severity breakdown
CRITICAL106HIGH646MEDIUM828LOW123
Vulnerabilities
Page 39 of 86
CVE-2026-43732P3MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-43732 [MEDIUM] CWE-22 CVE-2026-43732: A path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2,
A path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may disclose sensitive user information.
nvd
CVE-2025-43511P4MEDIUMCVSS 6.5fixed in 18.7.2fixed in 26.22025-12-12
CVE-2025-43511 [MEDIUM] CWE-416 CVE-2025-43511: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-64743P4MEDIUMCVSS 6.5fixed in 18.7.10fixed in 26.62026-07-27
CVE-2026-64743 [MEDIUM] CWE-285 CVE-2026-64743: An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.
nvd
CVE-2026-43740P4MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-43740 [MEDIUM] CWE-119 CVE-2026-43740: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may result in the disclosure of process memory.
nvd
CVE-2023-42961P4MEDIUMCVSS 6.3≥ unspecified, < 17≥ unspecified, < 16.72025-04-11
CVE-2023-42961 [MEDIUM] CWE-22 CVE-2023-42961: A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPad
A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPadOS 17, iOS 16.7 and iPadOS 16.7, macOS Sonoma 14, macOS Ventura 13.6, macOS Monterey 12.7. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2021-30996P4HIGHCVSS 7.0≥ unspecified, < 15.22021-08-24
CVE-2021-30996 [HIGH] CWE-362 CVE-2021-30996: A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 1
A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 12.1, iOS 15.2 and iPadOS 15.2. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2026-28941P4HIGHCVSS 7.1fixed in 18.7.92026-05-11
CVE-2026-28941 [HIGH] CWE-119 CVE-2026-28941: The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, m
The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Tahoe 26.5. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.
nvd
CVE-2022-22638P4MEDIUMCVSS 6.5≥ unspecified, < 15.42022-03-18
CVE-2022-22638 [MEDIUM] CWE-476 CVE-2022-22638: A null pointer dereference was addressed with improved validation. This issue is fixed in tvOS 15.4,
A null pointer dereference was addressed with improved validation. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, Security Update 2022-003 Catalina, watchOS 8.5, macOS Monterey 12.3. An attacker in a privileged position may be able to perform a denial of service attack.
nvd
CVE-2024-40787P4HIGHCVSS 7.1fixed in 17.62024-07-29
CVE-2024-40787 [HIGH] CVE-2024-40787: This issue was addressed by adding an additional prompt for user consent. This issue is fixed in iOS
This issue was addressed by adding an additional prompt for user consent. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, watchOS 10.6. A shortcut may be able to bypass Internet permission requirements.
nvd
CVE-2024-40774P4HIGHCVSS 7.1fixed in 17.62024-07-29
CVE-2024-40774 [HIGH] CVE-2024-40774: A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in iO
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, watchOS 10.6. An app may be able to bypass Privacy preferences.
nvd
CVE-2021-30887P4MEDIUMCVSS 6.5≥ unspecified, < 15.12021-08-24
CVE-2021-30887 [MEDIUM] CVE-2021-30887: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.0.1
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.0.1, iOS 15.1 and iPadOS 15.1, watchOS 8.1, tvOS 15.1. Processing maliciously crafted web content may lead to unexpectedly unenforced Content Security Policy.
nvd
CVE-2021-1811P4MEDIUMCVSS 6.5≥ unspecified, < 14.52021-09-08
CVE-2021-1811 [MEDIUM] CVE-2021-1811: A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.11.3 fo
A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.11.3 for Windows, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iCloud for Windows 12.3, macOS Big Sur 11.3, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing a maliciously crafted font may result in the disclosure of process memory.
nvd
CVE-2024-23280P4MEDIUMCVSS 6.5fixed in 17.42024-03-08
CVE-2024-23280 [MEDIUM] CWE-74 CVE-2024-23280: An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 1
An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A maliciously crafted webpage may be able to fingerprint the user.
nvd
CVE-2024-40789P4MEDIUMCVSS 6.5fixed in 16.7.9fixed in 17.62024-07-29
CVE-2024-40789 [MEDIUM] CWE-125 CVE-2024-40789: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Sa
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2025-43214P4MEDIUMCVSS 6.5fixed in 18.62025-07-30
CVE-2025-43214 [MEDIUM] CWE-119 CVE-2025-43214: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2024-23206P4MEDIUMCVSS 6.5fixed in 16.7.5fixed in 17.32024-01-23
CVE-2024-23206 [MEDIUM] CWE-200 CVE-2024-23206: An access issue was addressed with improved access restrictions. This issue is fixed in Safari 17.3,
An access issue was addressed with improved access restrictions. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. A maliciously crafted webpage may be able to fingerprint the user.
nvd
CVE-2025-43213P4MEDIUMCVSS 6.5fixed in 18.62025-07-30
CVE-2025-43213 [MEDIUM] CWE-119 CVE-2025-43213: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2023-27933P4MEDIUMCVSS 6.7≥ unspecified, < 16.42023-05-08
CVE-2023-27933 [MEDIUM] CWE-787 CVE-2023-27933: The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, iO
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, macOS Monterey 12.6.4, tvOS 16.4, watchOS 9.4. An app with root privileges may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2026-20690P4MEDIUMCVSS 6.5fixed in 18.7.7fixed in 26.42026-03-25
CVE-2026-20690 [MEDIUM] CWE-125 CVE-2026-20690: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. Processing an audio stream in a maliciously crafted media file may terminate the process.
nvd
CVE-2025-24194P4MEDIUMCVSS 6.5fixed in 18.42025-03-31
CVE-2025-24194 [MEDIUM] CVE-2025-24194: A logic issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, m
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may result in the disclosure of process memory.
nvd