Apple Ios And Ipados vulnerabilities
1,703 known vulnerabilities affecting apple/ios_and_ipados.
Total CVEs
1,703
CISA KEV
57
actively exploited
Public exploits
17
Exploited in wild
72
Severity breakdown
CRITICAL106HIGH646MEDIUM828LOW123
Vulnerabilities
Page 41 of 86
CVE-2023-42974P4HIGHCVSS 7.0≥ unspecified, < 17.2≥ unspecified, < 16.72024-03-28
CVE-2023-42974 [HIGH] CWE-362 CVE-2023-42974: A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 1
A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Sonoma 14.2. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2021-1820P4MEDIUMCVSS 6.5≥ unspecified, < 14.52021-09-08
CVE-2021-1820 [MEDIUM] CWE-665 CVE-2021-1820: A memory initialization issue was addressed with improved memory handling. This issue is fixed in ma
A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing maliciously crafted web content may result in the disclosure of process memory.
nvd
CVE-2025-24131P4MEDIUMCVSS 6.5fixed in 18.32025-01-27
CVE-2025-24131 [MEDIUM] CWE-120 CVE-2025-24131: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3. An attacker on the local network may be able to cause a denial-of-service.
nvd
CVE-2024-23254P4MEDIUMCVSS 6.5fixed in 17.42024-03-08
CVE-2024-23254 [MEDIUM] CVE-2024-23254: The issue was addressed with improved UI handling. This issue is fixed in Safari 17.4, iOS 17.4 and
The issue was addressed with improved UI handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. A malicious website may exfiltrate audio data cross-origin.
nvd
CVE-2023-40420P4MEDIUMCVSS 6.5≥ unspecified, < 17≥ unspecified, < 16.72023-09-27
CVE-2023-40420 [MEDIUM] CVE-2023-40420: The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tv
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may lead to a denial-of-service.
nvd
CVE-2023-40403P4MEDIUMCVSS 6.5≥ unspecified, < 17≥ unspecified, < 16.72023-09-27
CVE-2023-40403 [MEDIUM] CVE-2023-40403: The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tv
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may disclose sensitive information.
nvd
CVE-2025-43216P4MEDIUMCVSS 6.5fixed in 18.62025-07-30
CVE-2025-43216 [MEDIUM] CWE-416 CVE-2025-43216: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2025-31192P4MEDIUMCVSS 6.7fixed in 18.42025-03-31
CVE-2025-31192 [MEDIUM] CWE-305 CVE-2025-31192: The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadO
The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A website may be able to access sensor information without user consent.
nvd
CVE-2023-38133P4MEDIUMCVSS 6.5≥ unspecified, < 16.6≥ unspecified, < 15.72023-07-27
CVE-2023-38133 [MEDIUM] CVE-2023-38133: The issue was addressed with improved checks. This issue is fixed in iOS 15.7.8 and iPadOS 15.7.8, i
The issue was addressed with improved checks. This issue is fixed in iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Ventura 13.5, Safari 16.6, watchOS 9.6. Processing web content may disclose sensitive information.
nvd
CVE-2024-40782P4MEDIUMCVSS 6.5fixed in 16.7.9fixed in 17.62024-07-29
CVE-2024-40782 [MEDIUM] CWE-416 CVE-2024-40782: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2022-22659P4MEDIUMCVSS 6.5≥ unspecified, < 15.42022-03-18
CVE-2022-22659 [MEDIUM] CVE-2022-22659: A logic issue was addressed with improved state management. This issue is fixed in iOS 15.4 and iPad
A logic issue was addressed with improved state management. This issue is fixed in iOS 15.4 and iPadOS 15.4. An attacker in a privileged network position may be able to leak sensitive user information.
nvd
CVE-2025-24143P4MEDIUMCVSS 6.5fixed in 18.32025-01-27
CVE-2025-24143 [MEDIUM] CWE-862 CVE-2025-24143: The issue was addressed with improved access restrictions to the file system. This issue is fixed in
The issue was addressed with improved access restrictions to the file system. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, visionOS 2.3. A maliciously crafted webpage may be able to fingerprint the user.
nvd
CVE-2021-31001P4MEDIUMCVSS 6.5≥ unspecified, < 152021-08-24
CVE-2021-31001 [MEDIUM] CVE-2021-31001: An access issue was addressed with improved access restrictions. This issue is fixed in iOS 15 and i
An access issue was addressed with improved access restrictions. This issue is fixed in iOS 15 and iPadOS 15. An attacker in a privileged network position may be able to leak sensitive user information.
nvd
CVE-2024-27838P4MEDIUMCVSS 6.5fixed in 16.7.8fixed in 17.52024-06-10
CVE-2024-27838 [MEDIUM] CWE-79 CVE-2024-27838: The issue was addressed by adding additional logic. This issue is fixed in Safari 17.5, iOS 16.7.8 a
The issue was addressed by adding additional logic. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. A maliciously crafted webpage may be able to fingerprint the user.
nvd
CVE-2025-43356P4MEDIUMCVSS 6.5fixed in 18.7fixed in 262025-09-15
CVE-2025-43356 [MEDIUM] CWE-200 CVE-2025-43356: The issue was addressed with improved handling of caches. This issue is fixed in Safari 26, iOS 18.7
The issue was addressed with improved handling of caches. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. A website may be able to access sensor information without user consent.
nvd
CVE-2024-44187P4MEDIUMCVSS 6.5fixed in 182024-09-17
CVE-2024-44187 [MEDIUM] CWE-346 CVE-2024-44187: A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of se
A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. A malicious website may exfiltrate data cross-origin.
nvd
CVE-2026-43716P4MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-43716 [MEDIUM] CWE-119 CVE-2026-43716: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2026-20657P4MEDIUMCVSS 6.5fixed in 18.7.7fixed in 26.42026-03-25
CVE-2026-20657 [MEDIUM] CWE-119 CVE-2026-20657: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 18.7
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4. Parsing a maliciously crafted file may lead to an unexpected app termination.
nvd
CVE-2024-44155P4MEDIUMCVSS 6.5fixed in 17.7.1fixed in 182024-10-28
CVE-2024-44155 [MEDIUM] CVE-2024-44155: A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed
A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in Safari 18, iOS 17.7.1 and iPadOS 17.7.1, iOS 18 and iPadOS 18, macOS Sequoia 15, watchOS 11. Maliciously crafted web content may violate iframe sandboxing policy.
nvd
CVE-2023-42865P4MEDIUMCVSS 6.5≥ unspecified, < 16.42024-01-10
CVE-2023-42865 [MEDIUM] CWE-125 CVE-2023-42865: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ven
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3, tvOS 16.4, iOS 16.4 and iPadOS 16.4, watchOS 9.4. Processing an image may result in disclosure of process memory.
nvd