Apple Ios And Ipados vulnerabilities
1,703 known vulnerabilities affecting apple/ios_and_ipados.
Total CVEs
1,703
CISA KEV
57
actively exploited
Public exploits
17
Exploited in wild
72
Severity breakdown
CRITICAL106HIGH646MEDIUM828LOW123
Vulnerabilities
Page 7 of 86
CVE-2019-8751P3HIGHCVSS 8.8≥ unspecified, < 13.12020-10-27
CVE-2019-8751 [HIGH] CWE-787 CVE-2019-8751: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in Safari 13.0.1, iOS 13.1 and iPadOS 13.1, iCloud for Windows 10.7, iCloud for Windows 7.14, tvOS 13, watchOS 6, iTunes 12.10.1 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2023-35074P3HIGHCVSS 8.8≥ unspecified, < 172023-09-27
CVE-2023-35074 [HIGH] CVE-2023-35074: The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, Safari 17, wa
The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, Safari 17, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may lead to arbitrary code execution.
nvd
CVE-2021-30852P3HIGHCVSS 8.8≥ unspecified, < 14.8≥ unspecified, < 152021-08-24
CVE-2021-30852 [HIGH] CWE-843 CVE-2021-30852: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 14.8
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2023-38597P3HIGHCVSS 8.8≥ unspecified, < 16.6≥ unspecified, < 15.72023-07-27
CVE-2023-38597 [HIGH] CVE-2023-38597: The issue was addressed with improved checks. This issue is fixed in iOS 15.7.8 and iPadOS 15.7.8, i
The issue was addressed with improved checks. This issue is fixed in iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5, Safari 16.6. Processing web content may lead to arbitrary code execution.
nvd
CVE-2022-32912P3HIGHCVSS 8.8≥ unspecified, < 15.72022-09-20
CVE-2022-32912 [HIGH] CWE-125 CVE-2022-32912: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 16,
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2024-23226P3HIGHCVSS 8.8fixed in 17.42024-03-08
CVE-2024-23226 [HIGH] CWE-787 CVE-2024-23226: The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing web content may lead to arbitrary code execution.
nvd
CVE-2023-43010P3HIGHCVSS 8.8≥ unspecified, < 17.2≥ unspecified, < 16.7.15+1 more2026-03-12
CVE-2023-43010 [HIGH] CWE-787 CVE-2023-43010: The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS 16.7.15, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2024-27833P3HIGHCVSS 8.8fixed in 16.7.8fixed in 17.52024-06-10
CVE-2024-27833 [HIGH] CWE-190 CVE-2024-27833: An integer overflow was addressed with improved input validation. This issue is fixed in Safari 17.5
An integer overflow was addressed with improved input validation. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, tvOS 17.5, visionOS 1.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2026-65346P3HIGHCVSS 8.8fixed in 26.6.12026-08-17
CVE-2026-65346 [HIGH] CWE-190 CVE-2026-65346: An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing an image may lead to arbitrary code execution.
nvd
CVE-2021-1864P3CRITICALCVSS 9.8≥ unspecified, < 14.52021-09-08
CVE-2021-1864 [CRITICAL] CWE-416 CVE-2021-1864: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. An attacker with JavaScript execution may be able to execute arbitrary code.
nvd
CVE-2023-40414P3CRITICALCVSS 9.8≥ unspecified, < 172024-01-10
CVE-2023-40414 [CRITICAL] CWE-416 CVE-2023-40414: A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS
A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 10, iOS 17 and iPadOS 17, tvOS 17, macOS Sonoma 14, Safari 17. Processing web content may lead to arbitrary code execution.
nvd
CVE-2026-64770P3CRITICALCVSS 9.8fixed in 18.7.10fixed in 26.62026-07-27
CVE-2026-64770 [CRITICAL] CWE-787 CVE-2026-64770: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.
nvd
CVE-2026-64769P3CRITICALCVSS 9.8fixed in 18.7.10fixed in 26.62026-07-27
CVE-2026-64769 [CRITICAL] CWE-787 CVE-2026-64769: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.
nvd
CVE-2026-64726P3CRITICALCVSS 9.8fixed in 18.7.10fixed in 26.62026-07-27
CVE-2026-64726 [CRITICAL] CWE-119 CVE-2026-64726: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker in physical proximity may be able to corrupt process memory.
nvd
CVE-2026-28858P3CRITICALCVSS 9.8fixed in 26.42026-03-25
CVE-2026-28858 [CRITICAL] CWE-120 CVE-2026-28858: A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.4 and i
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2019-8846P3HIGHCVSS 8.8≥ unspecified, < 13.32020-10-27
CVE-2019-8846 [HIGH] CWE-416 CVE-2019-8846: A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 13
A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 13.3, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8830P3HIGHCVSS 8.8≥ unspecified, < 13.32020-10-27
CVE-2019-8830 [HIGH] CWE-125 CVE-2019-8830: An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 13.3
An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, iOS 13.3 and iPadOS 13.3, iOS 12.4.4, watchOS 5.3.4. Processing malicious video via FaceTime may lead to arbitrary code execution.
nvd
CVE-2021-30734P3HIGHCVSS 8.8≥ unspecified, < 14.62021-09-08
CVE-2021-30734 [HIGH] CWE-787 CVE-2021-30734: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2021-1817P3HIGHCVSS 8.8≥ unspecified, < 14.52021-09-08
CVE-2021-1817 [HIGH] CWE-787 CVE-2021-1817: A memory corruption issue was addressed with improved state management. This issue is fixed in macOS
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2021-1867P3HIGHCVSS 8.8≥ unspecified, < 14.52021-09-08
CVE-2021-1867 [HIGH] CWE-125 CVE-2021-1867: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.5
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.5 and iPadOS 14.5, macOS Big Sur 11.3. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd