Apple iPadOS vulnerabilities
1,906 known vulnerabilities affecting apple/ipados.
Total CVEs
1,906
CISA KEV
79
actively exploited
Public exploits
8
Exploited in wild
62
Severity breakdown
CRITICAL105HIGH848MEDIUM828LOW125
Vulnerabilities
Page 17 of 96
CVE-2025-43212MEDIUMCVSS 6.5fixed in 18.62025-07-30
CVE-2025-43212 [MEDIUM] CWE-119 CVE-2025-43212: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2025-31276MEDIUMCVSS 5.3fixed in 17.7.9≥ 18.0, < 18.62025-07-30
CVE-2025-31276 [MEDIUM] CWE-359 CVE-2025-31276: This issue was addressed through improved state management. This issue is fixed in iOS 18.6 and iPad
This issue was addressed through improved state management. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9. Remote content may be loaded even when the 'Load Remote Images' setting is turned off.
nvdapple
CVE-2025-7424HIGHCVSS 7.5v17.7.92025-07-29
CVE-2025-7424 [HIGH] CVE-2025-7424: iPadOS 17.7.9
Apple Security Update: About the security content of iPadOS 17.7.9
Product: iPadOS
Version: 17.7.9
CVE: CVE-2025-7424
Component: Kernel
Impact: An app may be able to cause unexpected system termination
Description: A double free issue was addressed with improved memory management.
apple
CVE-2025-6558HIGHCVSS 8.8KEVfixed in 18.62025-07-15
CVE-2025-6558 [HIGH] CWE-20 CVE-2025-6558: Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvdapple
CVE-2025-43200MEDIUMCVSS 4.2KEVfixed in 15.8.4≥ 16.0, < 16.7.11+3 more2025-06-16
CVE-2025-43200 [MEDIUM] CVE-2025-43200: This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4,
This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.7.4, visionOS 2.3.1, watchOS 11.3.1. A logic issue existed when processing a maliciously crafted photo or video shared via
nvdapple
CVE-2025-30466CRITICALCVSS 9.8fixed in 18.42025-05-29
CVE-2025-30466 [CRITICAL] CWE-346 CVE-2025-30466: This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS
This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4. A website may be able to bypass Same Origin Policy.
nvd
CVE-2025-31199MEDIUMCVSS 5.5fixed in 18.42025-05-29
CVE-2025-31199 [MEDIUM] CWE-532 CVE-2025-31199: A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPad
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.8.2, visionOS 2.4. An app may be able to access sensitive user data.
nvd
CVE-2025-24189HIGHCVSS 8.8fixed in 18.32025-05-19
CVE-2025-24189 [HIGH] CWE-119 CVE-2025-24189: The issue was addressed with improved checks. This issue is fixed in Safari 18.3, iOS 18.3 and iPadO
The issue was addressed with improved checks. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2025-31262MEDIUMCVSS 5.5fixed in 18.32025-05-19
CVE-2025-31262 [MEDIUM] CWE-732 CVE-2025-31262: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. An app may be able to modify protected parts of the file system.
nvd
CVE-2025-24184MEDIUMCVSS 5.5fixed in 17.7.4≥ 18.0, < 18.32025-05-19
CVE-2025-24184 [MEDIUM] CVE-2025-24184: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. An app may be able to cause unexpected system termination.
nvdapple
CVE-2025-31185LOWCVSS 3.3fixed in 18.32025-05-19
CVE-2025-31185 [LOW] CVE-2025-31185: A logic issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3. P
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3. Photos in the Hidden Photos Album may be viewed without authentication.
nvd
CVE-2025-30436CRITICALCVSS 9.1fixed in 18.42025-05-12
CVE-2025-30436 [CRITICAL] CWE-284 CVE-2025-30436: This issue was addressed by restricting options offered on a locked device. This issue is fixed in i
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.4 and iPadOS 18.4. An attacker may be able to use Siri to enable Auto-Answer Calls.
nvd
CVE-2025-30448CRITICALCVSS 9.1fixed in 17.7.7≥ 18.0, < 18.52025-05-12
CVE-2025-30448 [CRITICAL] CWE-862 CVE-2025-30448: This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.5 and iPa
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, visionOS 2.5. An attacker may be able to turn on sharing of an iCloud folder without authentication.
nvdapple
CVE-2025-24223HIGHCVSS 8.0fixed in 18.52025-05-12
CVE-2025-24223 [HIGH] CWE-352 CVE-2025-24223: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2025-31223HIGHCVSS 8.0fixed in 18.52025-05-12
CVE-2025-31223 [HIGH] CWE-119 CVE-2025-31223: The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadO
The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2025-31219HIGHCVSS 7.1fixed in 17.7.7≥ 18.0, < 18.52025-05-12
CVE-2025-31219 [HIGH] CWE-119 CVE-2025-31219: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.5 and iPadOS 18
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. An attacker may be able to cause unexpected system termination or corrupt kernel memory.
nvdapple
CVE-2025-31225HIGHCVSS 7.1fixed in 18.52025-05-12
CVE-2025-31225 [HIGH] CWE-200 CVE-2025-31225: A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.5 and iPadOS
A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.5 and iPadOS 18.5. Call history from deleted apps may still appear in spotlight search results.
nvd
CVE-2025-31214HIGHCVSS 8.1fixed in 18.52025-05-12
CVE-2025-31214 [HIGH] CWE-300 CVE-2025-31214: This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPad
This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPadOS 18.5. An attacker in a privileged network position may be able to intercept network traffic.
nvd
CVE-2025-31204HIGHCVSS 8.8fixed in 18.52025-05-12
CVE-2025-31204 [HIGH] CWE-119 CVE-2025-31204: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2025-31208HIGHCVSS 7.5fixed in 17.7.7≥ 18.0, < 18.52025-05-12
CVE-2025-31208 [HIGH] CWE-20 CVE-2025-31208: The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadO
The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. Parsing a file may lead to an unexpected app termination.
nvdapple