cbcvebase.

Apple Ios And Ipados vulnerabilities

1,703 known vulnerabilities affecting apple/ios_and_ipados.

Total CVEs
1,703
CISA KEV
57
actively exploited
Public exploits
17
Exploited in wild
72
Severity breakdown
CRITICAL106HIGH646MEDIUM828LOW123

Vulnerabilities

Page 79 of 86
CVE-2022-32795P4MEDIUMCVSS 4.3≥ unspecified, < 15.72022-09-20
CVE-2022-32795 [MEDIUM] CVE-2022-32795: This issue was addressed with improved checks. This issue is fixed in iOS 16, iOS 15.7 and iPadOS 15 This issue was addressed with improved checks. This issue is fixed in iOS 16, iOS 15.7 and iPadOS 15.7. Visiting a malicious website may lead to address bar spoofing.
nvd
CVE-2021-30999P4MEDIUMCVSS 4.3≥ unspecified, < 14.62021-08-24
CVE-2021-30999 [MEDIUM] CWE-276 CVE-2021-30999: The issue was addressed with improved permissions logic. This issue is fixed in iOS 14.6 and iPadOS The issue was addressed with improved permissions logic. This issue is fixed in iOS 14.6 and iPadOS 14.6. A user may be unable to fully delete browsing history.
nvd
CVE-2026-20609P4MEDIUMCVSS 4.4fixed in 18.7.5fixed in 26.32026-02-11
CVE-2026-20609 [MEDIUM] CWE-125 CVE-2026-20609: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.5 and iPadOS The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.
nvd
CVE-2024-54503P4MEDIUMCVSS 4.2fixed in 18.22024-12-12
CVE-2024-54503 [MEDIUM] CVE-2024-54503: An inconsistent user interface issue was addressed with improved state management. This issue is fix An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.2 and iPadOS 18.2. Muting a call while ringing may not result in mute being enabled.
nvd
CVE-2025-43226P4MEDIUMCVSS 4.0fixed in 18.62025-07-30
CVE-2025-43226 [MEDIUM] CWE-125 CVE-2025-43226: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.6 An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing a maliciously crafted image may result in disclosure of process memory.
nvd
CVE-2025-43205P4MEDIUMCVSS 4.0fixed in 18.42025-11-12
CVE-2025-43205 [MEDIUM] CWE-125 CVE-2025-43205: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to bypass ASLR.
nvd
CVE-2024-44136P4MEDIUMCVSS 4.6fixed in 17.52025-01-15
CVE-2024-44136 [MEDIUM] CWE-863 CVE-2024-44136: This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPad This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to a device may be able to disable Stolen Device Protection.
nvd
CVE-2021-30932P4MEDIUMCVSS 4.6≥ unspecified, < 15.22021-08-24
CVE-2021-30932 [MEDIUM] CVE-2021-30932: The issue was addressed with improved permissions logic. This issue is fixed in iOS 15.2 and iPadOS The issue was addressed with improved permissions logic. This issue is fixed in iOS 15.2 and iPadOS 15.2. A person with physical access to an iOS device may be able to access contacts from the lock screen.
nvd
CVE-2022-22622P4MEDIUMCVSS 4.6≥ unspecified, < 15.42022-03-18
CVE-2022-22622 [MEDIUM] CVE-2022-22622: This issue was addressed with improved checks. This issue is fixed in iOS 15.4 and iPadOS 15.4. A pe This issue was addressed with improved checks. This issue is fixed in iOS 15.4 and iPadOS 15.4. A person with physical access to an iOS device may be able to see sensitive information via keyboard suggestions.
nvd
CVE-2021-30699P4MEDIUMCVSS 4.6≥ unspecified, < 14.62021-09-08
CVE-2021-30699 [MEDIUM] CVE-2021-30699: A window management issue was addressed with improved state management. This issue is fixed in iOS 1 A window management issue was addressed with improved state management. This issue is fixed in iOS 14.6 and iPadOS 14.6. A user may be able to view restricted content from the lockscreen.
nvd
CVE-2026-20605P4MEDIUMCVSS 4.6fixed in 18.7.52026-02-11
CVE-2026-20605 [MEDIUM] CWE-119 CVE-2026-20605: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.5 and iPadOS The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to crash a system process.
nvd
CVE-2023-42855P4MEDIUMCVSS 4.6≥ unspecified, < 17.12024-02-21
CVE-2023-42855 [MEDIUM] CVE-2023-42855: This issue was addressed with improved state management. This issue is fixed in iOS 17.1 and iPadOS This issue was addressed with improved state management. This issue is fixed in iOS 17.1 and iPadOS 17.1. An attacker with physical access may be able to silently persist an Apple ID on an erased device.
nvd
CVE-2023-42934P4MEDIUMCVSS 4.2≥ unspecified, < 172024-01-10
CVE-2023-42934 [MEDIUM] CWE-200 CVE-2023-42934: An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed i An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An app with root privileges may be able to access private information.
nvd
CVE-2025-43230P4MEDIUMCVSS 4.0fixed in 18.62025-07-30
CVE-2025-43230 [MEDIUM] CWE-863 CVE-2025-43230: The issue was addressed with additional permissions checks. This issue is fixed in iOS 18.6 and iPad The issue was addressed with additional permissions checks. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. An app may be able to access user-sensitive data.
nvd
CVE-2021-1835P4MEDIUMCVSS 4.6≥ unspecified, < 14.52021-09-08
CVE-2021-1835 [MEDIUM] CWE-862 CVE-2021-1835: This issue was addressed with improved checks. This issue is fixed in iOS 14.5 and iPadOS 14.5. A pe This issue was addressed with improved checks. This issue is fixed in iOS 14.5 and iPadOS 14.5. A person with physical access to an iOS device may be able to access notes from the lock screen.
nvd
CVE-2023-42973P4MEDIUMCVSS 4.0≥ unspecified, < 172025-04-11
CVE-2023-42973 [MEDIUM] CWE-285 CVE-2023-42973: Private Browsing tabs may be accessed without authentication. This issue is fixed in iOS 17 and iPad Private Browsing tabs may be accessed without authentication. This issue is fixed in iOS 17 and iPadOS 17. The issue was addressed with improved UI.
nvd
CVE-2025-43203P4MEDIUMCVSS 4.0fixed in 18.7fixed in 262025-09-15
CVE-2025-43203 [MEDIUM] CWE-922 CVE-2025-43203: The issue was addressed with improved handling of caches. This issue is fixed in iOS 18.7 and iPadOS The issue was addressed with improved handling of caches. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26. An attacker with physical access to an unlocked device may be able to view an image in the most recently viewed locked note.
nvd
CVE-2026-28882P4MEDIUMCVSS 4.0fixed in 18.7.9fixed in 26.42026-03-25
CVE-2026-28882 [MEDIUM] CVE-2026-28882: This issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, This issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to enumerate a user's installed apps.
nvd
CVE-2021-1780P4MEDIUMCVSS 4.4≥ unspecified, < 14.42021-04-02
CVE-2021-1780 [MEDIUM] CWE-665 CVE-2021-1780: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iO A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 14.4 and iPadOS 14.4. An attacker in a privileged position may be able to perform a denial of service attack.
nvd
CVE-2025-43217P4MEDIUMCVSS 4.0fixed in 18.62025-07-30
CVE-2025-43217 [MEDIUM] CWE-359 CVE-2025-43217: The issue was addressed by adding additional logic. This issue is fixed in iOS 18.6 and iPadOS 18.6, The issue was addressed by adding additional logic. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9. Privacy Indicators for microphone or camera access may not be correctly displayed.
nvd
Apple Ios And Ipados vulnerabilities | cvebase