Apple iPadOS vulnerabilities
1,828 known vulnerabilities affecting apple/ipados.
Total CVEs
1,828
CISA KEV
79
actively exploited
Public exploits
5
Exploited in wild
62
Severity breakdown
CRITICAL105HIGH801MEDIUM799LOW123
Vulnerabilities
Page 12 of 92
CVE-2025-43349LOWCVSS 2.8fixed in 18.72025-09-15
CVE-2025-43349 [LOW] CWE-787 CVE-2025-43349: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iO
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing a maliciously crafted video file may lead to unexpected app termination.
nvd
CVE-2025-43357LOWCVSS 3.3fixed in 26.02025-09-15
CVE-2025-43357 [LOW] CWE-359 CVE-2025-43357: This issue was addressed with improved redaction of sensitive information. This issue is fixed in iO
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26. An app may be able to fingerprint the user.
nvd
CVE-2025-43300CRITICALCVSS 10.0KEVfixed in 15.8.5≥ 16.0, < 16.7.12+2 more2025-08-21
CVE-2025-43300 [CRITICAL] CWE-787 CVE-2025-43300: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, iOS 18.6.2 and iPadOS 18.6.2, iPadOS 17.7.10, macOS Sequoia 15.6.1, macOS Sonoma 14.7.8, macOS Ventura 13.7.8. Processing a malicious image file may result in memory corruption. Apple is awa
cvelistv5nvd
CVE-2025-43186CRITICALCVSS 9.8fixed in 18.62025-07-30
CVE-2025-43186 [CRITICAL] CWE-119 CVE-2025-43186: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Parsing a file may lead to an unexpected app termination.
nvd
CVE-2025-43222CRITICALCVSS 9.8fixed in 17.7.92025-07-30
CVE-2025-43222 [CRITICAL] CWE-416 CVE-2025-43222: A use-after-free issue was addressed by removing the vulnerable code. This issue is fixed in iPadOS
A use-after-free issue was addressed by removing the vulnerable code. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An attacker may be able to cause unexpected app termination.
cvelistv5nvd
CVE-2025-31229CRITICALCVSS 9.1fixed in 18.62025-07-30
CVE-2025-31229 [CRITICAL] CWE-261 CVE-2025-31229: A logic issue was addressed with improved checks. This issue is fixed in iOS 18.6 and iPadOS 18.6. P
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.6 and iPadOS 18.6. Passcode may be read aloud by VoiceOver.
nvd
CVE-2025-31281CRITICALCVSS 9.1fixed in 18.62025-07-30
CVE-2025-31281 [CRITICAL] CWE-20 CVE-2025-31281: An input validation issue was addressed with improved memory handling. This issue is fixed in iOS 18
An input validation issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6. Processing a maliciously crafted file may lead to unexpected app termination.
nvd
CVE-2025-43209CRITICALCVSS 9.8fixed in 17.7.9≥ 18.0, < 18.62025-07-30
CVE-2025-43209 [CRITICAL] CWE-787 CVE-2025-43209: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
cvelistv5nvd
CVE-2025-31279CRITICALCVSS 9.8fixed in 17.7.92025-07-30
CVE-2025-31279 [CRITICAL] CWE-200 CVE-2025-31279: A permissions issue was addressed with additional restrictions. This issue is fixed in iPadOS 17.7.9
A permissions issue was addressed with additional restrictions. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to fingerprint the user.
cvelistv5nvd
CVE-2025-43220CRITICALCVSS 9.8fixed in 17.7.92025-07-30
CVE-2025-43220 [CRITICAL] CWE-59 CVE-2025-43220: This issue was addressed with improved validation of symlinks. This issue is fixed in iPadOS 17.7.9,
This issue was addressed with improved validation of symlinks. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access protected user data.
cvelistv5nvd
CVE-2025-43234CRITICALCVSS 9.8fixed in 18.62025-07-30
CVE-2025-43234 [CRITICAL] CWE-20 CVE-2025-43234: Multiple memory corruption issues were addressed with improved input validation. This issue is fixed
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing a maliciously crafted texture may lead to unexpected app termination.
nvd
CVE-2025-31273HIGHCVSS 8.8fixed in 18.62025-07-30
CVE-2025-31273 [HIGH] CWE-119 CVE-2025-31273: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2025-31278HIGHCVSS 8.8fixed in 17.7.9≥ 18.0, < 18.62025-07-30
CVE-2025-31278 [HIGH] CWE-119 CVE-2025-31278: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.
cvelistv5nvd
CVE-2025-24224HIGHCVSS 7.5fixed in 17.7.9≥ 18.0, < 18.52025-07-30
CVE-2025-24224 [HIGH] CWE-754 CVE-2025-24224: The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadO
The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.9, macOS Sequoia 15.5, macOS Ventura 13.7.7, tvOS 18.5, visionOS 2.5, watchOS 11.5. A remote attacker may be able to cause unexpected system termination.
cvelistv5nvd
CVE-2025-43223HIGHCVSS 7.5fixed in 17.7.7≥ 18.0, < 18.6+1 more2025-07-30
CVE-2025-43223 [HIGH] CWE-20 CVE-2025-43223: A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 1
A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. A non-privileged user may be able to modify restricted network settings.
cvelistv5nvd
CVE-2025-43221HIGHCVSS 7.1fixed in 18.62025-07-30
CVE-2025-43221 [HIGH] CWE-125 CVE-2025-43221: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
nvd
CVE-2025-43227HIGHCVSS 7.5fixed in 18.62025-07-30
CVE-2025-43227 [HIGH] CWE-359 CVE-2025-43227: This issue was addressed through improved state management. This issue is fixed in Safari 18.6, iOS
This issue was addressed through improved state management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may disclose sensitive user information.
nvd
CVE-2025-31277HIGHCVSS 8.8KEVfixed in 18.62025-07-30
CVE-2025-31277 [HIGH] CWE-119 CVE-2025-31277: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2025-43224HIGHCVSS 7.1fixed in 18.62025-07-30
CVE-2025-43224 [HIGH] CWE-787 CVE-2025-43224: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
nvd
CVE-2025-43211MEDIUMCVSS 6.2fixed in 17.7.9≥ 18.0, < 18.62025-07-30
CVE-2025-43211 [MEDIUM] CWE-770 CVE-2025-43211: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing web content may lead to a denial-of-service.
cvelistv5nvd