Apple iPadOS vulnerabilities
1,906 known vulnerabilities affecting apple/ipados.
Total CVEs
1,906
CISA KEV
79
actively exploited
Public exploits
8
Exploited in wild
62
Severity breakdown
CRITICAL105HIGH848MEDIUM828LOW125
Vulnerabilities
Page 22 of 96
CVE-2025-24217MEDIUMCVSS 5.5fixed in 18.42025-03-31
CVE-2025-24217 [MEDIUM] CWE-200 CVE-2025-24217: This issue was addressed with improved redaction of sensitive information. This issue is fixed in iO
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, watchOS 11.4. An app may be able to access sensitive user data.
nvd
CVE-2025-24216MEDIUMCVSS 4.3fixed in 17.7.6≥ 18.0, < 18.42025-03-31
CVE-2025-24216 [MEDIUM] CWE-119 CVE-2025-24216: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
CVE-2025-24210MEDIUMCVSS 5.5fixed in 17.7.6≥ 18.0, < 18.42025-03-31
CVE-2025-24210 [MEDIUM] CWE-783 CVE-2025-24210: A logic error was addressed with improved error handling. This issue is fixed in iOS 18.4 and iPadOS
A logic error was addressed with improved error handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. Parsing an image may lead to disclosure of user information.
nvdapple
CVE-2025-31191MEDIUMCVSS 5.5fixed in 18.42025-03-31
CVE-2025-31191 [MEDIUM] CWE-200 CVE-2025-31191: This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPad
This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, watchOS 11.4. An app may be able to access sensitive user data.
nvd
CVE-2025-24192MEDIUMCVSS 6.5fixed in 18.42025-03-31
CVE-2025-24192 [MEDIUM] CVE-2025-24192: A script imports issue was addressed with improved isolation. This issue is fixed in Safari 18.4, iO
A script imports issue was addressed with improved isolation. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4. Visiting a website may leak sensitive data.
nvd
CVE-2025-24097MEDIUMCVSS 5.0fixed in 18.4fixed in 17.7.72025-03-31
CVE-2025-24097 [MEDIUM] CWE-125 CVE-2025-24097: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.4 and
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.5, tvOS 18.4, watchOS 11.4. An app may be able to read arbitrary file metadata.
nvdapple
CVE-2025-24182MEDIUMCVSS 5.5fixed in 18.42025-03-31
CVE-2025-24182 [MEDIUM] CWE-125 CVE-2025-24182: An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing a maliciously crafted font may result in the disclosure of process memory.
nvd
CVE-2025-24203MEDIUMCVSS 5.0fixed in 17.7.62025-03-31
CVE-2025-24203 [MEDIUM] CVE-2025-24203: The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadO
The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to modify protected parts of the file system.
nvdapple
CVE-2025-24244MEDIUMCVSS 5.5fixed in 17.7.6≥ 18.0, < 18.42025-03-31
CVE-2025-24244 [MEDIUM] CWE-200 CVE-2025-24244: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, watchOS 11.4. Processing a maliciously crafted font may result in the disclosure of process memory.
nvdapple
CVE-2025-30470MEDIUMCVSS 5.5fixed in 18.42025-03-31
CVE-2025-30470 [MEDIUM] CWE-22 CVE-2025-30470: A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.4 and iPadOS
A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, visionOS 2.4, watchOS 11.4. An app may be able to read sensitive location information.
nvd
CVE-2025-30434MEDIUMCVSS 5.0fixed in 18.42025-03-31
CVE-2025-30434 [MEDIUM] CWE-79 CVE-2025-30434: The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.4 and iPadOS
The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.4 and iPadOS 18.4. Processing a maliciously crafted file may lead to a cross site scripting attack.
nvd
CVE-2025-24202MEDIUMCVSS 5.5fixed in 18.42025-03-31
CVE-2025-24202 [MEDIUM] CWE-284 CVE-2025-24202: A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPad
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.
nvd
CVE-2025-30429MEDIUMCVSS 6.3fixed in 17.7.6≥ 18.0, < 18.42025-03-31
CVE-2025-30429 [MEDIUM] CVE-2025-30429: A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.4 and iP
A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to break out of its sandbox.
nvdapple
CVE-2025-30425MEDIUMCVSS 4.3fixed in 17.7.6≥ 18.0, < 18.42025-03-31
CVE-2025-30425 [MEDIUM] CWE-284 CVE-2025-30425: This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS
This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, watchOS 11.4. A malicious website may be able to track users in Safari private browsing mode.
nvdapple
CVE-2025-24214MEDIUMCVSS 5.5fixed in 18.42025-03-31
CVE-2025-24214 [MEDIUM] CWE-284 CVE-2025-24214: A privacy issue was addressed by not logging contents of text fields. This issue is fixed in iOS 18.
A privacy issue was addressed by not logging contents of text fields. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to access sensitive user data.
nvd
CVE-2025-30428MEDIUMCVSS 5.4fixed in 17.7.6≥ 18.0, < 18.42025-03-31
CVE-2025-30428 [MEDIUM] CWE-305 CVE-2025-30428: This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPad
This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6. Photos in the Hidden Photos Album may be viewed without authentication.
nvdapple
CVE-2025-24198MEDIUMCVSS 6.6fixed in 17.7.6≥ 18.0, < 18.42025-03-31
CVE-2025-24198 [MEDIUM] CWE-284 CVE-2025-24198: This issue was addressed by restricting options offered on a locked device. This issue is fixed in i
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker with physical access may be able to use Siri to access sensitive user data.
nvdapple
CVE-2025-24205MEDIUMCVSS 5.5fixed in 17.7.6≥ 18.0, < 18.42025-03-31
CVE-2025-24205 [MEDIUM] CWE-284 CVE-2025-24205: An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access user-sensitive data.
nvdapple
CVE-2025-24212MEDIUMCVSS 6.3fixed in 17.7.6≥ 18.0, < 18.42025-03-31
CVE-2025-24212 [MEDIUM] CVE-2025-24212: This issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPad
This issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to break out of its sandbox.
nvdapple
CVE-2025-30427MEDIUMCVSS 4.3fixed in 17.7.6≥ 18.0, < 18.42025-03-31
CVE-2025-30427 [MEDIUM] CWE-416 CVE-2025-30427: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple