Apple iPadOS vulnerabilities

1,828 known vulnerabilities affecting apple/ipados.

Total CVEs
1,828
CISA KEV
79
actively exploited
Public exploits
8
Exploited in wild
62
Severity breakdown
CRITICAL105HIGH801MEDIUM799LOW123

Vulnerabilities

Page 25 of 92
CVE-2024-40867CRITICALCVSS 9.6fixed in 18.12024-10-28
CVE-2024-40867 [CRITICAL] CVE-2024-40867: A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in iOS 18.1 and iPadOS 18.1. A remote attacker may be able to break out of Web Content sandbox.
nvd
CVE-2024-44252HIGHCVSS 7.1fixed in 17.7.1≥ 18.0, < 18.12024-10-28
CVE-2024-44252 [HIGH] CVE-2024-44252: A logic issue was addressed with improved file handling. This issue is fixed in iOS 17.7.1 and iPadO A logic issue was addressed with improved file handling. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, tvOS 18.1, visionOS 2.1. Restoring a maliciously crafted backup file may lead to modification of protected system files.
nvd
CVE-2024-44258HIGHCVSS 7.1fixed in 17.7.1≥ 18.0, < 18.12024-10-28
CVE-2024-44258 [HIGH] CWE-59 CVE-2024-44258: This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 17.7.1 and i This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, tvOS 18.1, visionOS 2.1. Restoring a maliciously crafted backup file may lead to modification of protected system files.
nvd
CVE-2024-44255HIGHCVSS 7.8fixed in 18.12024-10-28
CVE-2024-44255 [HIGH] CWE-22 CVE-2024-44255: A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. A malicious app may be able to run arbitrary shortcuts without user consent.
nvd
CVE-2024-44126HIGHCVSS 7.8fixed in 17.72024-10-28
CVE-2024-44126 [HIGH] CWE-787 CVE-2024-44126: The issue was addressed with improved checks. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 1 The issue was addressed with improved checks. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7.1, visionOS 2. Processing a maliciously crafted file may lead to heap corruption.
nvd
CVE-2024-44285HIGHCVSS 7.8≥ 18.0, < 18.12024-10-28
CVE-2024-44285 [HIGH] CWE-416 CVE-2024-44285: A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18. A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. An app may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2024-44277HIGHCVSS 7.8fixed in 18.12024-10-28
CVE-2024-44277 [HIGH] CWE-787 CVE-2024-44277: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.1 and iPadOS 18 The issue was addressed with improved memory handling. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1. An app may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2024-44218HIGHCVSS 7.8fixed in 17.7.1v18.02024-10-28
CVE-2024-44218 [HIGH] CWE-787 CVE-2024-44218: This issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, This issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1. Processing a maliciously crafted file may lead to heap corruption.
nvd
CVE-2024-44259HIGHCVSS 7.5fixed in 17.7.1≥ 18.0, < 18.12024-10-28
CVE-2024-44259 [HIGH] CVE-2024-44259: This issue was addressed through improved state management. This issue is fixed in Safari 18.1, iOS This issue was addressed through improved state management. This issue is fixed in Safari 18.1, iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, visionOS 2.1. An attacker may be able to misuse a trust relationship to download malicious content.
nvd
CVE-2024-44194MEDIUMCVSS 5.5fixed in 18.12024-10-28
CVE-2024-44194 [MEDIUM] CVE-2024-44194: This issue was addressed with improved redaction of sensitive information. This issue is fixed in iO This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, visionOS 2.1, watchOS 11.1. An app may be able to access sensitive user data.
nvd
CVE-2024-44240MEDIUMCVSS 5.5fixed in 17.7.1≥ 18.0, < 18.12024-10-28
CVE-2024-44240 [MEDIUM] CVE-2024-44240: The issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, i The issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Processing a maliciously crafted font may result in the disclosure of process memory.
nvd
CVE-2024-44254MEDIUMCVSS 5.5fixed in 18.12024-10-28
CVE-2024-44254 [MEDIUM] CVE-2024-44254: This issue was addressed with improved redaction of sensitive information. This issue is fixed in iO This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, watchOS 11.1. An app may be able to access sensitive user data.
nvd
CVE-2024-44145MEDIUMCVSS 6.1fixed in 18.02024-10-28
CVE-2024-44145 [MEDIUM] CVE-2024-44145: This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An attacker with physical access to a macOS device with Sidecar enabled may be able to bypass the Lock Screen.
nvd
CVE-2024-44155MEDIUMCVSS 6.5fixed in 17.7.12024-10-28
CVE-2024-44155 [MEDIUM] CVE-2024-44155: A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in Safari 18, iOS 17.7.1 and iPadOS 17.7.1, iOS 18 and iPadOS 18, macOS Sequoia 15, watchOS 11. Maliciously crafted web content may violate iframe sandboxing policy.
nvd
CVE-2024-44269MEDIUMCVSS 5.5fixed in 17.7.1≥ 18.0, < 18.12024-10-28
CVE-2024-44269 [MEDIUM] CVE-2024-44269: A logic issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7. A logic issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, visionOS 2.1, watchOS 11.1. A malicious app may use shortcuts to access restricted files.
nvd
CVE-2024-44229MEDIUMCVSS 5.3fixed in 18.12024-10-28
CVE-2024-44229 [MEDIUM] CVE-2024-44229: An information leakage was addressed with additional validation. This issue is fixed in Safari 18.1, An information leakage was addressed with additional validation. This issue is fixed in Safari 18.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, visionOS 2.1. Private browsing may leak some browsing history.
nvd
CVE-2024-44273MEDIUMCVSS 5.5fixed in 18.12024-10-28
CVE-2024-44273 [MEDIUM] CWE-59 CVE-2024-44273: This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.1 and iPa This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. A malicious app may be able to access private information.
nvd
CVE-2024-44235MEDIUMCVSS 4.6fixed in 18.12024-10-28
CVE-2024-44235 [MEDIUM] CWE-754 CVE-2024-44235: The issue was addressed with improved checks. This issue is fixed in iOS 18.1 and iPadOS 18.1. An at The issue was addressed with improved checks. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to view restricted content from the lock screen.
nvd
CVE-2024-44263MEDIUMCVSS 5.5fixed in 18.12024-10-28
CVE-2024-44263 [MEDIUM] CWE-922 CVE-2024-44263: A logic issue was addressed with improved state management. This issue is fixed in iOS 18.1 and iPad A logic issue was addressed with improved state management. This issue is fixed in iOS 18.1 and iPadOS 18.1. An app may be able to access user-sensitive data.
nvd
CVE-2024-44144MEDIUMCVSS 5.5fixed in 17.7.12024-10-28
CVE-2024-44144 [MEDIUM] CWE-120 CVE-2024-44144: A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 17.7.1 and A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7.1, tvOS 18, visionOS 2, watchOS 11. Processing a maliciously crafted file may lead to unexpected app termination.
nvd