Apple Ios And Ipados vulnerabilities
1,656 known vulnerabilities affecting apple/ios_and_ipados.
Total CVEs
1,656
CISA KEV
57
actively exploited
Public exploits
17
Exploited in wild
72
Severity breakdown
CRITICAL100HIGH640MEDIUM796LOW120
Vulnerabilities
Page 73 of 83
CVE-2024-54535P4MEDIUMCVSS 4.3fixed in 18.12025-01-15
CVE-2024-54535 [MEDIUM] CWE-22 CVE-2024-54535: A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS
A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, visionOS 2.1, watchOS 11.1. An attacker with access to calendar data could also read reminders.
nvd
CVE-2025-43503P4MEDIUMCVSS 4.3fixed in 18.7.2fixed in 26.12025-11-04
CVE-2025-43503 [MEDIUM] CWE-290 CVE-2025-43503: An inconsistent user interface issue was addressed with improved state management. This issue is fix
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Visiting a malicious website may lead to user interface spoofing.
nvd
CVE-2026-43708P4MEDIUMCVSS 4.3fixed in 26.5.22026-06-29
CVE-2026-43708 [MEDIUM] CWE-20 CVE-2026-43708: The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26
The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may exfiltrate data cross-origin.
nvd
CVE-2026-28861P4MEDIUMCVSS 4.3fixed in 18.7.7fixed in 26.42026-03-25
CVE-2026-28861 [MEDIUM] CWE-79 CVE-2026-28861: A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS
A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. A malicious website may be able to access script message handlers intended for other origins.
nvd
CVE-2026-28917P4MEDIUMCVSS 4.3fixed in 18.7.9fixed in 26.52026-05-11
CVE-2026-28917 [MEDIUM] CWE-20 CVE-2026-28917: The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7
The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2025-46316P4MEDIUMCVSS 4.3fixed in 26.12026-01-28
CVE-2025-46316 [MEDIUM] CWE-125 CVE-2025-46316: An out-of-bounds read was addressed with improved input validation. This issue is fixed in Pages 15.
An out-of-bounds read was addressed with improved input validation. This issue is fixed in Pages 15.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. Processing a maliciously crafted Pages document may result in unexpected termination or disclosure of process memory.
nvd
CVE-2026-28871P4MEDIUMCVSS 4.3fixed in 18.7.7fixed in 26.42026-03-25
CVE-2026-28871 [MEDIUM] CWE-79 CVE-2026-28871: A logic issue was addressed with improved checks. This issue is fixed in Safari 26.4, iOS 18.7.7 and
A logic issue was addressed with improved checks. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4. Visiting a maliciously crafted website may lead to a cross-site scripting attack.
nvd
CVE-2023-38614P4MEDIUMCVSS 4.3≥ unspecified, < 172025-04-11
CVE-2023-38614 [MEDIUM] CWE-269 CVE-2023-38614: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iP
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to access sensitive user data.
nvd
CVE-2020-27925P4MEDIUMCVSS 5.5≥ unspecified, < 14.22020-12-08
CVE-2020-27925 [MEDIUM] CVE-2020-27925: An issue existed in the handling of incoming calls. The issue was addressed with additional state ch
An issue existed in the handling of incoming calls. The issue was addressed with additional state checks. This issue is fixed in iOS 14.2 and iPadOS 14.2. A user may answer two calls simultaneously without indication they have answered a second call.
nvd
CVE-2024-23201P4MEDIUMCVSS 5.5fixed in 17.32024-03-08
CVE-2024-23201 [MEDIUM] CWE-276 CVE-2024-23201: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.3 and
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.4, macOS Sonoma 14.3, macOS Ventura 13.6.5, tvOS 17.3, watchOS 10.3. An app may be able to cause a denial-of-service.
nvd
CVE-2022-32946P4MEDIUMCVSS 5.5≥ unspecified, < 16.12022-11-01
CVE-2022-32946 [MEDIUM] CWE-284 CVE-2022-32946: This issue was addressed with improved entitlements. This issue is fixed in iOS 16.1 and iPadOS 16.
This issue was addressed with improved entitlements. This issue is fixed in iOS 16.1 and iPadOS 16. An app may be able to record audio using a pair of connected AirPods.
nvd
CVE-2025-43355P4MEDIUMCVSS 5.5fixed in 18.7fixed in 262025-09-15
CVE-2025-43355 [MEDIUM] CWE-843 CVE-2025-43355: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 18.7
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An app may be able to cause a denial-of-service.
nvd
CVE-2023-38593P4MEDIUMCVSS 5.5≥ unspecified, < 16.62023-07-27
CVE-2023-38593 [MEDIUM] CVE-2023-38593: A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.8, iOS
A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.8, iOS 16.6 and iPadOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to cause a denial-of-service.
nvd
CVE-2021-1865P4MEDIUMCVSS 5.0≥ unspecified, < 14.52021-09-08
CVE-2021-1865 [MEDIUM] CWE-312 CVE-2021-1865: An issue obscuring passwords in screenshots was addressed with improved logic. This issue is fixed i
An issue obscuring passwords in screenshots was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14.5. A user's password may be visible on screen.
nvd
CVE-2024-23239P4MEDIUMCVSS 4.7fixed in 17.42024-03-08
CVE-2024-23239 [MEDIUM] CWE-362 CVE-2024-23239: A race condition was addressed with improved state handling. This issue is fixed in iOS 17.4 and iPa
A race condition was addressed with improved state handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to leak sensitive user information.
nvd
CVE-2023-41997P4MEDIUMCVSS 4.6≥ unspecified, < 16.7≥ unspecified, < 17.12023-10-25
CVE-2023-41997 [MEDIUM] CVE-2023-41997: This issue was addressed by restricting options offered on a locked device. This issue is fixed in m
This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sonoma 14.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1. An attacker with physical access may be able to use Siri to access sensitive user data.
nvd
CVE-2023-41982P4MEDIUMCVSS 4.6≥ unspecified, < 16.7≥ unspecified, < 17.12023-10-25
CVE-2023-41982 [MEDIUM] CVE-2023-41982: This issue was addressed by restricting options offered on a locked device. This issue is fixed in m
This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sonoma 14.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1. An attacker with physical access may be able to use Siri to access sensitive user data.
nvd
CVE-2024-44274P4MEDIUMCVSS 4.6fixed in 17.7.1fixed in 18.12024-10-28
CVE-2024-44274 [MEDIUM] CVE-2024-44274: The issue was addressed with improved authentication. This issue is fixed in iOS 17.7.1 and iPadOS 1
The issue was addressed with improved authentication. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, watchOS 11.1. An attacker with physical access to a locked device may be able to view sensitive user information.
nvd
CVE-2024-40818P4MEDIUMCVSS 4.6fixed in 16.7.9fixed in 17.62024-07-29
CVE-2024-40818 [MEDIUM] CVE-2024-40818: This issue was addressed by restricting options offered on a locked device. This issue is fixed in i
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, watchOS 10.6. An attacker with physical access may be able to use Siri to access sensitive user data.
nvd
CVE-2024-23251P4MEDIUMCVSS 4.6fixed in 16.7.8fixed in 17.52024-06-10
CVE-2024-23251 [MEDIUM] CWE-287 CVE-2024-23251: An authentication issue was addressed with improved state management. This issue is fixed in iOS 16.
An authentication issue was addressed with improved state management. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, watchOS 10.5. An attacker with physical access may be able to leak Mail account credentials.
nvd