cbcvebase.

Apple Ios And Ipados vulnerabilities

1,703 known vulnerabilities affecting apple/ios_and_ipados.

Total CVEs
1,703
CISA KEV
57
actively exploited
Public exploits
17
Exploited in wild
72
Severity breakdown
CRITICAL106HIGH646MEDIUM828LOW123

Vulnerabilities

Page 75 of 86
CVE-2026-28861P4MEDIUMCVSS 4.3fixed in 18.7.7fixed in 26.42026-03-25
CVE-2026-28861 [MEDIUM] CWE-79 CVE-2026-28861: A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. A malicious website may be able to access script message handlers intended for other origins.
nvd
CVE-2025-46299P4MEDIUMCVSS 4.3fixed in 26.22026-01-09
CVE-2025-46299 [MEDIUM] CWE-284 CVE-2025-46299: A memory initialization issue was addressed with improved memory handling. This issue is fixed in Sa A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may disclose internal states of the app.
nvd
CVE-2026-28917P4MEDIUMCVSS 4.3fixed in 18.7.9fixed in 26.52026-05-11
CVE-2026-28917 [MEDIUM] CWE-20 CVE-2026-28917: The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7 The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2025-46316P4MEDIUMCVSS 4.3fixed in 26.12026-01-28
CVE-2025-46316 [MEDIUM] CWE-125 CVE-2025-46316: An out-of-bounds read was addressed with improved input validation. This issue is fixed in Pages 15. An out-of-bounds read was addressed with improved input validation. This issue is fixed in Pages 15.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. Processing a maliciously crafted Pages document may result in unexpected termination or disclosure of process memory.
nvd
CVE-2026-28871P4MEDIUMCVSS 4.3fixed in 18.7.7fixed in 26.42026-03-25
CVE-2026-28871 [MEDIUM] CWE-79 CVE-2026-28871: A logic issue was addressed with improved checks. This issue is fixed in Safari 26.4, iOS 18.7.7 and A logic issue was addressed with improved checks. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4. Visiting a maliciously crafted website may lead to a cross-site scripting attack.
nvd
CVE-2023-38614P4MEDIUMCVSS 4.3≥ unspecified, < 172025-04-11
CVE-2023-38614 [MEDIUM] CWE-269 CVE-2023-38614: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iP A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to access sensitive user data.
nvd
CVE-2020-27925P4MEDIUMCVSS 5.5≥ unspecified, < 14.22020-12-08
CVE-2020-27925 [MEDIUM] CVE-2020-27925: An issue existed in the handling of incoming calls. The issue was addressed with additional state ch An issue existed in the handling of incoming calls. The issue was addressed with additional state checks. This issue is fixed in iOS 14.2 and iPadOS 14.2. A user may answer two calls simultaneously without indication they have answered a second call.
nvd
CVE-2024-23201P4MEDIUMCVSS 5.5fixed in 17.32024-03-08
CVE-2024-23201 [MEDIUM] CWE-276 CVE-2024-23201: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.3 and A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.4, macOS Sonoma 14.3, macOS Ventura 13.6.5, tvOS 17.3, watchOS 10.3. An app may be able to cause a denial-of-service.
nvd
CVE-2022-32946P4MEDIUMCVSS 5.5≥ unspecified, < 16.12022-11-01
CVE-2022-32946 [MEDIUM] CWE-284 CVE-2022-32946: This issue was addressed with improved entitlements. This issue is fixed in iOS 16.1 and iPadOS 16. This issue was addressed with improved entitlements. This issue is fixed in iOS 16.1 and iPadOS 16. An app may be able to record audio using a pair of connected AirPods.
nvd
CVE-2025-43355P4MEDIUMCVSS 5.5fixed in 18.7fixed in 262025-09-15
CVE-2025-43355 [MEDIUM] CWE-843 CVE-2025-43355: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 18.7 A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An app may be able to cause a denial-of-service.
nvd
CVE-2025-43295P4MEDIUMCVSS 5.5fixed in 18.72025-09-15
CVE-2025-43295 [MEDIUM] CWE-400 CVE-2025-43295: A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7 an A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7 and iPadOS 18.7, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to cause a denial-of-service.
nvd
CVE-2025-43299P4MEDIUMCVSS 5.5fixed in 18.72025-09-15
CVE-2025-43299 [MEDIUM] CWE-20 CVE-2025-43299: A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7 an A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7 and iPadOS 18.7, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to cause a denial-of-service.
nvd
CVE-2023-38593P4MEDIUMCVSS 5.5≥ unspecified, < 16.62023-07-27
CVE-2023-38593 [MEDIUM] CVE-2023-38593: A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.8, iOS A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.8, iOS 16.6 and iPadOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to cause a denial-of-service.
nvd
CVE-2025-31202P4MEDIUMCVSS 5.5fixed in 18.42025-04-29
CVE-2025-31202 [MEDIUM] CWE-476 CVE-2025-31202: A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4. An attacker on the local network may be able to cause a denial-of-service.
nvd
CVE-2021-1865P4MEDIUMCVSS 5.0≥ unspecified, < 14.52021-09-08
CVE-2021-1865 [MEDIUM] CWE-312 CVE-2021-1865: An issue obscuring passwords in screenshots was addressed with improved logic. This issue is fixed i An issue obscuring passwords in screenshots was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14.5. A user's password may be visible on screen.
nvd
CVE-2024-23239P4MEDIUMCVSS 4.7fixed in 17.42024-03-08
CVE-2024-23239 [MEDIUM] CWE-362 CVE-2024-23239: A race condition was addressed with improved state handling. This issue is fixed in iOS 17.4 and iPa A race condition was addressed with improved state handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to leak sensitive user information.
nvd
CVE-2023-41997P4MEDIUMCVSS 4.6≥ unspecified, < 16.7≥ unspecified, < 17.12023-10-25
CVE-2023-41997 [MEDIUM] CVE-2023-41997: This issue was addressed by restricting options offered on a locked device. This issue is fixed in m This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sonoma 14.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1. An attacker with physical access may be able to use Siri to access sensitive user data.
nvd
CVE-2023-41982P4MEDIUMCVSS 4.6≥ unspecified, < 16.7≥ unspecified, < 17.12023-10-25
CVE-2023-41982 [MEDIUM] CVE-2023-41982: This issue was addressed by restricting options offered on a locked device. This issue is fixed in m This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sonoma 14.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1. An attacker with physical access may be able to use Siri to access sensitive user data.
nvd
CVE-2024-44274P4MEDIUMCVSS 4.6fixed in 17.7.1fixed in 18.12024-10-28
CVE-2024-44274 [MEDIUM] CVE-2024-44274: The issue was addressed with improved authentication. This issue is fixed in iOS 17.7.1 and iPadOS 1 The issue was addressed with improved authentication. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, watchOS 11.1. An attacker with physical access to a locked device may be able to view sensitive user information.
nvd
CVE-2024-40818P4MEDIUMCVSS 4.6fixed in 16.7.9fixed in 17.62024-07-29
CVE-2024-40818 [MEDIUM] CVE-2024-40818: This issue was addressed by restricting options offered on a locked device. This issue is fixed in i This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, watchOS 10.6. An attacker with physical access may be able to use Siri to access sensitive user data.
nvd
Apple Ios And Ipados vulnerabilities | cvebase