Apple iPadOS vulnerabilities

1,828 known vulnerabilities affecting apple/ipados.

Total CVEs
1,828
CISA KEV
79
actively exploited
Public exploits
8
Exploited in wild
62
Severity breakdown
CRITICAL105HIGH801MEDIUM799LOW123

Vulnerabilities

Page 22 of 92
CVE-2025-24113MEDIUMCVSS 4.3fixed in 18.3fixed in 17.7.62025-01-27
CVE-2025-24113 [MEDIUM] CVE-2025-24113: The issue was addressed with improved UI. This issue is fixed in Safari 18.3, Safari 18.4, iOS 18.3 The issue was addressed with improved UI. This issue is fixed in Safari 18.3, Safari 18.4, iOS 18.3 and iPadOS 18.3, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sequoia 15.4, visionOS 2.3, visionOS 2.4, watchOS 11.4. Visiting a malicious website may lead to user interface spoofing.
cvelistv5nvd
CVE-2025-24160MEDIUMCVSS 4.3fixed in 17.7.4≥ 18.0, < 18.32025-01-27
CVE-2025-24160 [MEDIUM] CWE-404 CVE-2025-24160: The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadO The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Parsing a file may lead to an unexpected app termination.
cvelistv5nvd
CVE-2024-54518MEDIUMCVSS 5.3fixed in 18.22025-01-27
CVE-2024-54518 [MEDIUM] CWE-125 CVE-2024-54518: The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.2 and iPadOS 18.2 The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, watchOS 11.2. An app may be able to corrupt coprocessor memory.
nvd
CVE-2025-24086MEDIUMCVSS 5.5fixed in 17.7.4≥ 18.0, < 18.32025-01-27
CVE-2025-24086 [MEDIUM] CWE-770 CVE-2025-24086: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18 The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Processing an image may lead to a denial-of-service.
cvelistv5nvd
CVE-2025-24162MEDIUMCVSS 6.5fixed in 18.32025-01-27
CVE-2025-24162 [MEDIUM] CWE-125 CVE-2025-24162: This issue was addressed through improved state management. This issue is fixed in Safari 18.3, iOS This issue was addressed through improved state management. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2025-24104MEDIUMCVSS 5.5fixed in 17.7.4≥ 18.0, < 18.32025-01-27
CVE-2025-24104 [MEDIUM] CWE-59 CVE-2025-24104: This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.3 and iPa This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4. Restoring a maliciously crafted backup file may lead to modification of protected system files.
cvelistv5nvd
CVE-2025-24127MEDIUMCVSS 5.5fixed in 17.7.4≥ 18.0, < 18.32025-01-27
CVE-2025-24127 [MEDIUM] CWE-770 CVE-2025-24127: The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadO The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.3, visionOS 2.3. Parsing a file may lead to an unexpected app termination.
cvelistv5nvd
CVE-2024-54478MEDIUMCVSS 6.5fixed in 17.7.4≥ 18.0, < 18.22025-01-27
CVE-2024-54478 [MEDIUM] CWE-125 CVE-2024-54478: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.4, macOS Sequoia 15.2, macOS Sonoma 14.7.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to an unexpected process crash.
cvelistv5nvd
CVE-2024-54523MEDIUMCVSS 6.3fixed in 18.22025-01-27
CVE-2024-54523 [MEDIUM] CWE-787 CVE-2024-54523: The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.2 and iPadOS 18.2 The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, watchOS 11.2. An app may be able to corrupt coprocessor memory.
nvd
CVE-2025-24131MEDIUMCVSS 6.5fixed in 18.3fixed in 17.7.62025-01-27
CVE-2025-24131 [MEDIUM] CWE-120 CVE-2025-24131: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18 The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3. An attacker on the local network may be able to cause a denial-of-service.
cvelistv5nvd
CVE-2025-24158MEDIUMCVSS 6.5fixed in 18.32025-01-27
CVE-2025-24158 [MEDIUM] CWE-79 CVE-2025-24158: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.3, iOS 18.3 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Processing web content may lead to a denial-of-service.
nvd
CVE-2025-24163MEDIUMCVSS 5.5fixed in 17.7.4≥ 18.0, < 18.32025-01-27
CVE-2025-24163 [MEDIUM] CVE-2025-24163: The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iOS 1 The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sequoia 15.4, macOS Sonoma 14.7.3, tvOS 18.3, tvOS 18.4, visionOS 2.3, visionOS 2.4, watchOS 11.3, watchOS 11.4. Parsing a file may lead to an unexpected app termination.
cvelistv5nvd
CVE-2025-24149MEDIUMCVSS 5.5fixed in 17.7.4≥ 18.0, < 18.32025-01-27
CVE-2025-24149 [MEDIUM] CWE-125 CVE-2025-24149: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.3 a An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Parsing a file may lead to disclosure of user information.
cvelistv5nvd
CVE-2025-24123MEDIUMCVSS 5.5fixed in 17.7.4≥ 18.0, < 18.32025-01-27
CVE-2025-24123 [MEDIUM] CVE-2025-24123: The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadO The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Parsing a file may lead to an unexpected app termination.
cvelistv5nvd
CVE-2024-54541MEDIUMCVSS 5.5fixed in 18.22025-01-27
CVE-2024-54541 [MEDIUM] CWE-922 CVE-2024-54541: This issue was addressed through improved state management. This issue is fixed in iOS 18.2 and iPad This issue was addressed through improved state management. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. An app may be able to access user-sensitive data.
nvd
CVE-2024-54550MEDIUMCVSS 4.0fixed in 18.22025-01-27
CVE-2024-54550 [MEDIUM] CWE-200 CVE-2024-54550: This issue was addressed with improved redaction of sensitive information. This issue is fixed in iO This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2. An app may be able to view autocompleted contact information from Messages and Mail in system logs.
nvd
CVE-2025-24128MEDIUMCVSS 4.3fixed in 18.32025-01-27
CVE-2025-24128 [MEDIUM] CVE-2025-24128: The issue was addressed by adding additional logic. This issue is fixed in Safari 18.3, iOS 18.3 and The issue was addressed by adding additional logic. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. Visiting a malicious website may lead to address bar spoofing.
nvd
CVE-2025-24141LOWCVSS 3.3fixed in 18.32025-01-27
CVE-2025-24141 [LOW] CWE-863 CVE-2025-24141: An authentication issue was addressed with improved state management. This issue is fixed in iOS 18. An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3. An attacker with physical access to an unlocked device may be able to access Photos while the app is locked.
nvd
CVE-2025-24145LOWCVSS 3.3fixed in 18.32025-01-27
CVE-2025-24145 [LOW] CWE-532 CVE-2025-24145: A privacy issue was addressed with improved private data redaction for log entries. This issue is fi A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. An app may be able to view a contact's phone number in system logs.
nvd
CVE-2024-40771HIGHCVSS 7.8fixed in 16.7.8≥ 17.0, < 17.52025-01-15
CVE-2024-40771 [HIGH] CWE-863 CVE-2024-40771: The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.2, watchOS 10.5. An app may be able to execute arbitrary code with kernel privileges.
nvd