Apple Ios And Ipados vulnerabilities
1,656 known vulnerabilities affecting apple/ios_and_ipados.
Total CVEs
1,656
CISA KEV
57
actively exploited
Public exploits
17
Exploited in wild
72
Severity breakdown
CRITICAL100HIGH640MEDIUM796LOW120
Vulnerabilities
Page 75 of 83
CVE-2023-32385P4MEDIUMCVSS 5.5≥ unspecified, < 16.52023-06-23
CVE-2023-32385 [MEDIUM] CWE-770 CVE-2023-32385: A denial-of-service issue was addressed with improved memory handling. This issue is fixed in iOS 16
A denial-of-service issue was addressed with improved memory handling. This issue is fixed in iOS 16.5 and iPadOS 16.5, macOS Ventura 13.4. Opening a PDF file may lead to unexpected app termination.
nvd
CVE-2024-23293P4MEDIUMCVSS 4.6fixed in 17.42024-03-08
CVE-2024-23293 [MEDIUM] CVE-2024-23293: This issue was addressed through improved state management. This issue is fixed in iOS 17.4 and iPad
This issue was addressed through improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An attacker with physical access may be able to use Siri to access sensitive user data.
nvd
CVE-2026-28992P4MEDIUMCVSS 4.7fixed in 18.7.9fixed in 26.52026-05-11
CVE-2026-28992 [MEDIUM] CWE-362 CVE-2026-28992: A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An attacker may be able to cause unexpected app termination.
nvd
CVE-2025-30439P4MEDIUMCVSS 4.6fixed in 18.42025-03-31
CVE-2025-30439 [MEDIUM] CWE-200 CVE-2025-30439: The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS
The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. An attacker with physical access to a locked device may be able to view sensitive user information.
nvd
CVE-2024-40813P4MEDIUMCVSS 4.6fixed in 17.62024-07-29
CVE-2024-40813 [MEDIUM] CWE-922 CVE-2024-40813: A lock screen issue was addressed with improved state management. This issue is fixed in iOS 17.6 an
A lock screen issue was addressed with improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, watchOS 10.6. An attacker with physical access may be able to use Siri to access sensitive user data.
nvd
CVE-2020-9993P4MEDIUMCVSS 4.3≥ unspecified, < 14.02020-12-08
CVE-2020-9993 [MEDIUM] CWE-1021 CVE-2020-9993: The issue was addressed with improved UI handling. This issue is fixed in watchOS 7.0, Safari 14.0,
The issue was addressed with improved UI handling. This issue is fixed in watchOS 7.0, Safari 14.0, iOS 14.0 and iPadOS 14.0. Visiting a malicious website may lead to address bar spoofing.
nvd
CVE-2023-42897P4MEDIUMCVSS 4.6≥ unspecified, < 17.22023-12-12
CVE-2023-42897 [MEDIUM] CVE-2023-42897: The issue was addressed with improved checks. This issue is fixed in iOS 17.2 and iPadOS 17.2. An at
The issue was addressed with improved checks. This issue is fixed in iOS 17.2 and iPadOS 17.2. An attacker with physical access may be able to use Siri to access sensitive user data.
nvd
CVE-2020-27902P4MEDIUMCVSS 4.6≥ unspecified, < 14.22020-12-08
CVE-2020-27902 [MEDIUM] CWE-306 CVE-2020-27902: An authentication issue was addressed with improved state management. This issue is fixed in iOS 14.
An authentication issue was addressed with improved state management. This issue is fixed in iOS 14.2 and iPadOS 14.2. A person with physical access to an iOS device may be able to access stored passwords without authentication.
nvd
CVE-2021-30948P4MEDIUMCVSS 4.6≥ unspecified, < 15.22021-08-24
CVE-2021-30948 [MEDIUM] CWE-522 CVE-2021-30948: An inconsistent user interface issue was addressed with improved state management. This issue is fix
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 15.2 and iPadOS 15.2. A person with physical access to an iOS device may be able to access stored passwords without authentication.
nvd
CVE-2022-22621P4MEDIUMCVSS 4.6≥ unspecified, < 15.42022-03-18
CVE-2022-22621 [MEDIUM] CVE-2022-22621: This issue was addressed with improved checks. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS
This issue was addressed with improved checks. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3, watchOS 8.5. A person with physical access to an iOS device may be able to see sensitive information via keyboard suggestions.
nvd
CVE-2024-44171P4MEDIUMCVSS 4.6fixed in 17.7fixed in 182024-09-17
CVE-2024-44171 [MEDIUM] CVE-2024-44171: This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPad
This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, watchOS 11. An attacker with physical access to a locked device may be able to Control Nearby Devices via accessibility features.
nvd
CVE-2024-54470P4MEDIUMCVSS 4.6fixed in 17.7.1fixed in 18.12025-01-15
CVE-2024-54470 [MEDIUM] CWE-862 CVE-2024-54470: A logic issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.
A logic issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1. An attacker with physical access may be able to access contacts from the lock screen.
nvd
CVE-2024-40840P4MEDIUMCVSS 4.6fixed in 182024-09-17
CVE-2024-40840 [MEDIUM] CVE-2024-40840: This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS
This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical access may be able to use Siri to access sensitive user data.
nvd
CVE-2025-31227P4MEDIUMCVSS 4.6fixed in 18.52025-05-12
CVE-2025-31227 [MEDIUM] CWE-863 CVE-2025-31227: A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. A
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. An attacker with physical access to a device may be able to access a deleted call recording.
nvd
CVE-2026-28895P4MEDIUMCVSS 4.6fixed in 26.42026-03-25
CVE-2026-28895 [MEDIUM] CWE-284 CVE-2026-28895: The issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. An at
The issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. An attacker with physical access to an iOS device with Stolen Device Protection enabled may be able to access biometrics-gated Protected Apps with the passcode.
nvd
CVE-2025-43418P4MEDIUMCVSS 4.6fixed in 18.7.2fixed in 26.12025-11-05
CVE-2025-43418 [MEDIUM] CWE-284 CVE-2025-43418: This issue was addressed by restricting options offered on a locked device. This issue is fixed in i
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An attacker with physical access to a locked device may be able to view sensitive user information.
nvd
CVE-2026-20661P4MEDIUMCVSS 4.6fixed in 18.7.5fixed in 26.32026-02-11
CVE-2026-20661 [MEDIUM] CWE-285 CVE-2026-20661: An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.
nvd
CVE-2026-20645P4MEDIUMCVSS 4.6fixed in 18.7.5fixed in 26.32026-02-11
CVE-2026-20645 [MEDIUM] CWE-1021 CVE-2026-20645: An inconsistent user interface issue was addressed with improved state management. This issue is fix
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.
nvd
CVE-2026-20674P4MEDIUMCVSS 4.6fixed in 26.32026-02-11
CVE-2026-20674 [MEDIUM] CWE-200 CVE-2026-20674: A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.3 and iPadOS
A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.
nvd
CVE-2021-1854P4MEDIUMCVSS 4.3≥ unspecified, < 14.52021-09-08
CVE-2021-1854 [MEDIUM] CWE-863 CVE-2021-1854: A call termination issue with was addressed with improved logic. This issue is fixed in iOS 14.5 and
A call termination issue with was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14.5. A legacy cellular network can automatically answer an incoming call when an ongoing call ends or drops. .
nvd