cbcvebase.

Apple Ios And Ipados vulnerabilities

1,656 known vulnerabilities affecting apple/ios_and_ipados.

Total CVEs
1,656
CISA KEV
57
actively exploited
Public exploits
17
Exploited in wild
72
Severity breakdown
CRITICAL100HIGH640MEDIUM796LOW120

Vulnerabilities

Page 44 of 83
CVE-2026-43746P4MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-43746 [MEDIUM] CWE-416 CVE-2026-43746: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2026-43734P4MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-43734 [MEDIUM] CWE-416 CVE-2026-43734: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-43709P4MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-43709 [MEDIUM] CWE-416 CVE-2026-43709: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-43699P4MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-43699 [MEDIUM] CWE-416 CVE-2026-43699: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-43726P4MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-43726 [MEDIUM] CWE-416 CVE-2026-43726: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-43717P4MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-43717 [MEDIUM] CWE-416 CVE-2026-43717: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2024-23218P4MEDIUMCVSS 5.9fixed in 16.7.6fixed in 17.32024-01-23
CVE-2024-23218 [MEDIUM] CWE-203 CVE-2024-23218: A timing side-channel issue was addressed with improvements to constant-time computation in cryptogr A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.4, macOS Sonoma 14.3, macOS Ventura 13.6.5, tvOS 17.3, watchOS 10.3. An attacker may be able to decrypt legacy RSA PKCS#1 v1.5 cipherte
nvd
CVE-2024-44176P4MEDIUMCVSS 5.5fixed in 17.7fixed in 182024-09-17
CVE-2024-44176 [MEDIUM] CWE-400 CVE-2024-44176: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7, tvOS 18, visionOS 2, watchOS 11. Processing an image may lead to a denial-of-service.
nvd
CVE-2024-54494P4MEDIUMCVSS 5.9fixed in 18.22024-12-12
CVE-2024-54494 [MEDIUM] CWE-362 CVE-2024-54494: A race condition was addressed with additional validation. This issue is fixed in iOS 18.2 and iPadO A race condition was addressed with additional validation. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. An attacker may be able to create a read-only memory mapping that can be written to.
nvd
CVE-2024-40777P4MEDIUMCVSS 5.5fixed in 17.62024-07-29
CVE-2024-40777 [MEDIUM] CWE-787 CVE-2024-40777: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing a maliciously crafted file may lead to unexpected app termination.
nvd
CVE-2026-28886P4MEDIUMCVSS 5.9fixed in 18.7.7fixed in 26.42026-03-25
CVE-2026-28886 [MEDIUM] CWE-476 CVE-2026-28886: A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. A user in a privileged network position may be able to cause a denial-of-service.
nvd
CVE-2024-40799P4HIGHCVSS 7.1fixed in 16.7.9fixed in 17.62024-07-29
CVE-2024-40799 [HIGH] CWE-125 CVE-2024-40799: An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing a maliciously crafted file may lead to unexpected app termination.
nvd
CVE-2023-32357P4HIGHCVSS 7.1≥ unspecified, < 16.52023-06-23
CVE-2023-32357 [HIGH] CWE-125 CVE-2023-32357: An authorization issue was addressed with improved state management. This issue is fixed in watchOS An authorization issue was addressed with improved state management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. An app may be able to retain access to system configuration files even after its permission is revoked.
nvd
CVE-2026-64725P4HIGHCVSS 7.1fixed in 26.62026-07-27
CVE-2026-64725 [HIGH] CWE-787 CVE-2026-64725: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause a denial-of-service.
nvd
CVE-2021-30659P4MEDIUMCVSS 6.5≥ unspecified, < 14.52021-09-08
CVE-2021-30659 [MEDIUM] CVE-2021-30659: A validation issue was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14. A validation issue was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, macOS Big Sur 11.3. A malicious application may be able to leak sensitive user information.
nvd
CVE-2024-54497P4MEDIUMCVSS 6.5fixed in 18.22025-01-27
CVE-2024-54497 [MEDIUM] CWE-770 CVE-2024-54497: The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadO The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.4, macOS Sequoia 15.2, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing web content may lead to a denial-of-service.
nvd
CVE-2024-23271P4MEDIUMCVSS 6.5fixed in 17.32024-04-24
CVE-2024-23271 [MEDIUM] CWE-284 CVE-2024-23271: A logic issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 17.3 and i A logic issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. A malicious website may cause unexpected cross-origin behavior.
nvd
CVE-2025-24192P4MEDIUMCVSS 6.5fixed in 18.42025-03-31
CVE-2025-24192 [MEDIUM] CVE-2025-24192: A script imports issue was addressed with improved isolation. This issue is fixed in Safari 18.4, iO A script imports issue was addressed with improved isolation. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4. Visiting a website may leak sensitive data.
nvd
CVE-2022-32784P4MEDIUMCVSS 6.5≥ unspecified, < 15.62023-02-27
CVE-2022-32784 [MEDIUM] CWE-200 CVE-2022-32784: The issue was addressed with improved UI handling. This issue is fixed in Safari 15.6, iOS 15.6 and The issue was addressed with improved UI handling. This issue is fixed in Safari 15.6, iOS 15.6 and iPadOS 15.6. Visiting a maliciously crafted website may leak sensitive data.
nvd
CVE-2026-43663P4MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-43663 [MEDIUM] CWE-119 CVE-2026-43663: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26. The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd