Apple Ios And Ipados vulnerabilities
1,656 known vulnerabilities affecting apple/ios_and_ipados.
Total CVEs
1,656
CISA KEV
57
actively exploited
Public exploits
17
Exploited in wild
72
Severity breakdown
CRITICAL100HIGH640MEDIUM796LOW120
Vulnerabilities
Page 45 of 83
CVE-2026-39872P4MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-39872 [MEDIUM] CWE-119 CVE-2026-39872: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2024-54492P4MEDIUMCVSS 5.9fixed in 18.22024-12-12
CVE-2024-54492 [MEDIUM] CVE-2024-54492: This issue was addressed by using HTTPS when sending information over the network. This issue is fix
This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, visionOS 2.2. An attacker in a privileged network position may be able to alter network traffic.
nvd
CVE-2023-42898P4MEDIUMCVSS 5.5≥ unspecified, < 17.22023-12-12
CVE-2023-42898 [MEDIUM] CVE-2023-42898: The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2, wat
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2, watchOS 10.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2. Processing an image may lead to arbitrary code execution.
nvd
CVE-2026-20687P4HIGHCVSS 7.1fixed in 18.7.7fixed in 26.42026-03-25
CVE-2026-20687 [HIGH] CWE-416 CVE-2026-20687: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Tahoe 26.4, tvOS 26.4, watchOS 26.4. An app may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2024-44252P4HIGHCVSS 7.1fixed in 17.7.1fixed in 18.12024-10-28
CVE-2024-44252 [HIGH] CVE-2024-44252: A logic issue was addressed with improved file handling. This issue is fixed in iOS 17.7.1 and iPadO
A logic issue was addressed with improved file handling. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, tvOS 18.1, visionOS 2.1. Restoring a maliciously crafted backup file may lead to modification of protected system files.
nvd
CVE-2025-43224P4HIGHCVSS 7.1fixed in 18.62025-07-30
CVE-2025-43224 [HIGH] CWE-787 CVE-2025-43224: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
nvd
CVE-2025-24257P4HIGHCVSS 7.1fixed in 18.42025-03-31
CVE-2025-24257 [HIGH] CWE-787 CVE-2025-24257: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iO
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. An app may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2025-43338P4HIGHCVSS 7.1fixed in 262025-11-04
CVE-2025-43338 [HIGH] CWE-79 CVE-2025-43338: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26 and iPadOS 26, macOS Sonoma 14.8.2, macOS Sonoma 14.8.4, macOS Tahoe 26. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
nvd
CVE-2025-43221P4HIGHCVSS 7.1fixed in 18.62025-07-30
CVE-2025-43221 [HIGH] CWE-125 CVE-2025-43221: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
nvd
CVE-2026-20641P4HIGHCVSS 7.1fixed in 18.7.5fixed in 26.32026-02-11
CVE-2026-20641 [HIGH] CWE-200 CVE-2026-20641: A privacy issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.
A privacy issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to identify what other apps a user has installed.
nvd
CVE-2026-20628P4HIGHCVSS 7.1fixed in 18.7.5fixed in 26.32026-02-11
CVE-2026-20628 [HIGH] CWE-284 CVE-2026-20628: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.5 an
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to break out of its sandbox.
nvd
CVE-2024-23259P4MEDIUMCVSS 6.5fixed in 16.7.6fixed in 17.42024-03-08
CVE-2024-23259 [MEDIUM] CWE-400 CVE-2024-23259: The issue was addressed with improved checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, i
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Processing web content may lead to a denial-of-service.
nvd
CVE-2024-54526P4MEDIUMCVSS 5.5fixed in 18.22024-12-12
CVE-2024-54526 [MEDIUM] CVE-2024-54526: The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS
The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, watchOS 11.2. A malicious app may be able to access private information.
nvd
CVE-2021-1825P4MEDIUMCVSS 6.1≥ unspecified, < 14.52021-09-08
CVE-2021-1825 [MEDIUM] CWE-79 CVE-2021-1825: An input validation issue was addressed with improved input validation. This issue is fixed in iTune
An input validation issue was addressed with improved input validation. This issue is fixed in iTunes 12.11.3 for Windows, iCloud for Windows 12.3, macOS Big Sur 11.3, Safari 14.1, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may lead to a cross site scripting attack.
nvd
CVE-2021-30890P4MEDIUMCVSS 6.1≥ unspecified, < 15.12021-08-24
CVE-2021-30890 [MEDIUM] CWE-79 CVE-2021-30890: A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1, iOS 15.1 and iPadOS 15.1, watchOS 8.1, tvOS 15.1. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
CVE-2024-40785P4MEDIUMCVSS 6.1fixed in 16.7.9fixed in 17.62024-07-29
CVE-2024-40785 [MEDIUM] CWE-79 CVE-2024-40785: This issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 16.7.9 and iP
This issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to a cross site scripting attack.
nvd
CVE-2024-40857P4MEDIUMCVSS 6.1fixed in 182024-09-17
CVE-2024-40857 [MEDIUM] CWE-79 CVE-2024-40857: This issue was addressed through improved state management. This issue is fixed in Safari 18, iOS 18
This issue was addressed through improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
CVE-2024-23277P4MEDIUMCVSS 5.9fixed in 17.42024-03-08
CVE-2024-23277 [MEDIUM] CVE-2024-23277: The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS
The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An attacker in a privileged network position may be able to inject keystrokes by spoofing a keyboard.
nvd
CVE-2023-42846P4MEDIUMCVSS 5.3≥ unspecified, < 16.7≥ unspecified, < 17.12023-10-25
CVE-2023-42846 [MEDIUM] CWE-200 CVE-2023-42846: This issue was addressed by removing the vulnerable code. This issue is fixed in watchOS 10.1, iOS 1
This issue was addressed by removing the vulnerable code. This issue is fixed in watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, tvOS 17.1, iOS 17.1 and iPadOS 17.1. A device may be passively tracked by its Wi-Fi MAC address.
nvd
CVE-2024-27834P4MEDIUMCVSS 5.5fixed in 16.7.8fixed in 17.52024-05-14
CVE-2024-27834 [MEDIUM] CWE-277 CVE-2024-27834: The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPa
The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, watchOS 10.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
nvd