Apple iPadOS vulnerabilities
1,945 known vulnerabilities affecting apple/ipados.
Total CVEs
1,945
CISA KEV
79
actively exploited
Public exploits
36
Exploited in wild
111
Severity breakdown
CRITICAL106HIGH857MEDIUM857LOW125
Vulnerabilities
Page 15 of 98
CVE-2023-41060P3HIGHCVSS 8.8fixed in 17.02024-01-10
CVE-2023-41060 [HIGH] CWE-843 CVE-2023-41060: A type confusion issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14, i
A type confusion issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. A remote user may be able to cause kernel code execution.
nvd
CVE-2023-42833P3HIGHCVSS 8.8fixed in 17.02024-01-10
CVE-2023-42833 [HIGH] CWE-94 CVE-2023-42833: A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14, Safa
A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14, Safari 17, iOS 17 and iPadOS 17. Processing web content may lead to arbitrary code execution.
nvd
CVE-2025-43431P3HIGHCVSS 8.8fixed in 26.12025-11-04
CVE-2025-43431 [HIGH] CWE-787 CVE-2025-43431: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2024-54543P3HIGHCVSS 8.8fixed in 18.2fixed in 17.7.62025-01-27
CVE-2024-54543 [HIGH] CWE-787 CVE-2024-54543: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to memory corruption.
nvdapple
CVE-2022-32922P3HIGHCVSS 8.8fixed in 16.02022-11-01
CVE-2022-32922 [HIGH] CWE-416 CVE-2022-32922: A use after free issue was addressed with improved memory management. This issue is fixed in Safari
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2026-28955P3HIGHCVSS 8.8fixed in 18.7.9≥ 26.0, < 26.52026-05-11
CVE-2026-28955 [HIGH] CWE-119 CVE-2026-28955: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-28847P3HIGHCVSS 8.8fixed in 18.7.9≥ 26.0, < 26.52026-05-11
CVE-2026-28847 [HIGH] CWE-119 CVE-2026-28847: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2023-32358P3HIGHCVSS 8.8≥ 16.0, < 16.42023-08-14
CVE-2023-32358 [HIGH] CWE-843 CVE-2023-32358: A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.4 and iPadO
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.4 and iPadOS 16.4, macOS Ventura 13.3. Processing web content may lead to arbitrary code execution.
nvd
CVE-2025-43202P3HIGHCVSS 8.8fixed in 18.62026-04-02
CVE-2025-43202 [HIGH] CWE-787 CVE-2025-43202: This issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 1
This issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6. Processing a file may lead to memory corruption.
nvd
CVE-2026-43705P3HIGHCVSS 8.8fixed in 26.5.22026-06-29
CVE-2026-43705 [HIGH] CWE-843 CVE-2026-43705: A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2026-28947P3HIGHCVSS 8.8fixed in 26.52026-05-11
CVE-2026-28947 [HIGH] CWE-416 CVE-2026-28947: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2025-43419P3HIGHCVSS 8.8fixed in 26.02025-11-04
CVE-2025-43419 [HIGH] CWE-119 CVE-2025-43419: The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and
The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2025-24211P3CRITICALCVSS 9.8fixed in 17.7.6≥ 18.0, < 18.42025-03-31
CVE-2025-24211 [CRITICAL] CWE-400 CVE-2025-24211: This issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 1
This issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4. Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory.
nvdapple
CVE-2020-9883P3HIGHCVSS 7.8fixed in 13.62020-10-22
CVE-2020-9883 [HIGH] CWE-120 CVE-2020-9883: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2022-32847P3CRITICALCVSS 9.1fixed in 15.62022-09-23
CVE-2022-32847 [CRITICAL] CWE-119 CVE-2022-32847: This issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macO
This issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2025-43209P3CRITICALCVSS 9.8fixed in 17.7.9≥ 18.0, < 18.62025-07-30
CVE-2025-43209 [CRITICAL] CWE-787 CVE-2025-43209: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
CVE-2025-43347P3CRITICALCVSS 9.8fixed in 26.02025-09-15
CVE-2025-43347 [CRITICAL] CWE-20 CVE-2025-43347: This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26 and iPadOS 2
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An input validation issue was addressed.
nvd
CVE-2013-0340P3MEDIUMCVSS 6.8fixed in 14.82014-01-21
CVE-2013-0340 [MEDIUM] CWE-611 CVE-2013-0340: expat before version 2.4.0 does not properly handle entities expansion unless an application develop
expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE
nvd
CVE-2021-1874P3HIGHCVSS 8.8fixed in 14.52021-09-08
CVE-2021-1874 [HIGH] CVE-2021-1874: A logic issue was addressed with improved state management. This issue is fixed in iOS 14.5 and iPad
A logic issue was addressed with improved state management. This issue is fixed in iOS 14.5 and iPadOS 14.5. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2024-54542P3CRITICALCVSS 9.1fixed in 18.22025-01-27
CVE-2024-54542 [CRITICAL] CWE-862 CVE-2024-54542: An authentication issue was addressed with improved state management. This issue is fixed in Safari
An authentication issue was addressed with improved state management. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, watchOS 11.2. Private Browsing tabs may be accessed without authentication.
nvd