Apple iPadOS vulnerabilities

1,828 known vulnerabilities affecting apple/ipados.

Total CVEs
1,828
CISA KEV
79
actively exploited
Public exploits
8
Exploited in wild
62
Severity breakdown
CRITICAL105HIGH801MEDIUM799LOW123

Vulnerabilities

Page 23 of 92
CVE-2024-27856HIGHCVSS 7.8fixed in 16.7.8≥ 17.0, < 17.52025-01-15
CVE-2024-27856 [HIGH] CWE-94 CVE-2024-27856: The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPa The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing a file may lead to unexpected app termination or arbitrary code execution.
nvd
CVE-2024-54535MEDIUMCVSS 4.3fixed in 18.12025-01-15
CVE-2024-54535 [MEDIUM] CWE-22 CVE-2024-54535: A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, visionOS 2.1, watchOS 11.1. An attacker with access to calendar data could also read reminders.
nvd
CVE-2024-44136MEDIUMCVSS 4.6fixed in 17.52025-01-15
CVE-2024-44136 [MEDIUM] CWE-863 CVE-2024-44136: This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPad This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to a device may be able to disable Stolen Device Protection.
nvd
CVE-2024-54470MEDIUMCVSS 4.6fixed in 17.7.1v18.02025-01-15
CVE-2024-54470 [MEDIUM] CWE-862 CVE-2024-54470: A logic issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7. A logic issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1. An attacker with physical access may be able to access contacts from the lock screen.
nvd
CVE-2024-40854MEDIUMCVSS 5.5fixed in 17.7.1≥ 18.0, < 18.12025-01-15
CVE-2024-40854 [MEDIUM] CVE-2024-40854: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iO A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An app may be able to cause unexpected system termination.
nvd
CVE-2024-40839LOWCVSS 2.4fixed in 17.52025-01-15
CVE-2024-40839 [LOW] CWE-862 CVE-2024-40839: This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPad This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to an iOS device may be able to view notification contents from the Lock Screen.
nvd
CVE-2024-54538HIGHCVSS 7.5fixed in 17.7.1≥ 18.0, < 18.12024-12-20
CVE-2024-54538 [HIGH] CWE-770 CVE-2024-54538: A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 1 A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. A remote attacker may be able to cause a denial-of-service.
nvd
CVE-2024-54534CRITICALCVSS 9.8fixed in 18.2fixed in 17.7.62024-12-12
CVE-2024-54534 [CRITICAL] CWE-787 CVE-2024-54534: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to memory corruption.
cvelistv5nvd
CVE-2024-44299CRITICALCVSS 9.8fixed in 18.12024-12-12
CVE-2024-44299 [CRITICAL] CVE-2024-44299: The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1 The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP firmware.
nvd
CVE-2024-44242CRITICALCVSS 9.8fixed in 18.12024-12-12
CVE-2024-44242 [CRITICAL] CWE-787 CVE-2024-44242: The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1 The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP firmware.
nvd
CVE-2024-44241CRITICALCVSS 9.8fixed in 18.12024-12-12
CVE-2024-44241 [CRITICAL] CWE-770 CVE-2024-44241: The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1 The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP firmware.
nvd
CVE-2024-44225HIGHCVSS 7.8fixed in 17.7.3≥ 18.0, < 18.22024-12-12
CVE-2024-44225 [HIGH] CVE-2024-44225: A logic issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, i A logic issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, watchOS 11.2. An app may be able to gain elevated privileges.
cvelistv5nvd
CVE-2024-54479HIGHCVSS 7.5fixed in 17.7.3≥ 18.0, < 18.22024-12-12
CVE-2024-54479 [HIGH] CVE-2024-54479: The issue was addressed with improved checks. This issue is fixed in Safari 18.2, iOS 18.2 and iPadO The issue was addressed with improved checks. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to an unexpected process crash.
cvelistv5nvd
CVE-2024-44245HIGHCVSS 7.1fixed in 17.7.3≥ 18.0, < 18.22024-12-12
CVE-2024-44245 [HIGH] CWE-787 CVE-2024-44245: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.2 and iPadOS 18 The issue was addressed with improved memory handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, visionOS 2.2. An app may be able to cause unexpected system termination or corrupt kernel memory.
cvelistv5nvd
CVE-2024-54508HIGHCVSS 7.5fixed in 18.2fixed in 17.7.62024-12-12
CVE-2024-54508 [HIGH] CVE-2024-54508: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to an unexpected process crash.
cvelistv5nvd
CVE-2024-54505HIGHCVSS 8.8fixed in 17.7.3≥ 18.0, < 18.22024-12-12
CVE-2024-54505 [HIGH] CWE-843 CVE-2024-54505: A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 18 A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to memory corruption.
cvelistv5nvd
CVE-2024-54514HIGHCVSS 8.6fixed in 18.22024-12-12
CVE-2024-54514 [HIGH] CVE-2024-54514: The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, watchOS 11.2. An app may be able to break out of its sandbox.
nvd
CVE-2024-54494MEDIUMCVSS 5.9fixed in 17.7.3≥ 18.0, < 18.22024-12-12
CVE-2024-54494 [MEDIUM] CWE-362 CVE-2024-54494: A race condition was addressed with additional validation. This issue is fixed in iOS 18.2 and iPadO A race condition was addressed with additional validation. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. An attacker may be able to create a read-only memory mapping that can be written to.
cvelistv5nvd
CVE-2024-54500MEDIUMCVSS 5.5fixed in 17.7.3≥ 18.0, < 18.22024-12-12
CVE-2024-54500 [MEDIUM] CVE-2024-54500: The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadO The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing a maliciously crafted image may result in disclosure of process memory.
cvelistv5nvd
CVE-2024-54526MEDIUMCVSS 5.5fixed in 18.22024-12-12
CVE-2024-54526 [MEDIUM] CVE-2024-54526: The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, watchOS 11.2. A malicious app may be able to access private information.
nvd