cbcvebase.

Apple iPadOS vulnerabilities

2,004 known vulnerabilities affecting apple/ipados.

Total CVEs
2,004
CISA KEV
79
actively exploited
Public exploits
36
Exploited in wild
111
Severity breakdown
CRITICAL127HIGH877MEDIUM875LOW125

Vulnerabilities

Page 38 of 101
CVE-2026-20652P3HIGHCVSS 7.5fixed in 18.7.5≥ 26.0, < 26.32026-02-11
CVE-2026-20652 [HIGH] CWE-400 CVE-2026-20652: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7. The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. A remote attacker may be able to cause a denial-of-service.
nvd
CVE-2025-43220P3CRITICALCVSS 9.8fixed in 17.7.92025-07-30
CVE-2025-43220 [CRITICAL] CWE-59 CVE-2025-43220: This issue was addressed with improved validation of symlinks. This issue is fixed in iPadOS 17.7.9, This issue was addressed with improved validation of symlinks. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access protected user data.
nvdapple
CVE-2025-43436P3HIGHCVSS 7.5fixed in 26.12025-11-04
CVE-2025-43436 [HIGH] CWE-288 CVE-2025-43436: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.1 and A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. An app may be able to enumerate a user's installed apps.
nvd
CVE-2026-20650P3HIGHCVSS 7.5fixed in 26.32026-02-11
CVE-2026-20650 [HIGH] CWE-400 CVE-2026-20650: A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 26.3 an A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker in a privileged network position may be able to perform denial-of-service attack using crafted Bluetooth packets.
nvd
CVE-2026-28872P3HIGHCVSS 7.5fixed in 18.7.9≥ 26.0, < 26.42026-05-11
CVE-2026-28872 [HIGH] CWE-400 CVE-2026-28872: A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4. A remote attacker may be able to cause a denial-of-service.
nvd
CVE-2026-43661P3HIGHCVSS 7.5fixed in 26.52026-05-11
CVE-2026-43661 [HIGH] CWE-121 CVE-2026-43661: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 26.5 A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. Processing a maliciously crafted image may corrupt process memory.
nvd
CVE-2026-28943P3HIGHCVSS 7.5fixed in 18.7.9≥ 26.0, < 26.52026-05-11
CVE-2026-28943 [HIGH] CWE-532 CVE-2026-28943: A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iP A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to determine kernel memory layout.
nvd
CVE-2025-43502P3HIGHCVSS 7.5fixed in 26.12025-11-04
CVE-2025-43502 [HIGH] CWE-284 CVE-2025-43502: A privacy issue was addressed by removing sensitive data. This issue is fixed in Safari 26.1, iOS 26 A privacy issue was addressed by removing sensitive data. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1. An app may be able to bypass certain Privacy preferences.
nvd
CVE-2025-43454P3HIGHCVSS 7.5fixed in 26.12025-11-04
CVE-2025-43454 [HIGH] CWE-284 CVE-2025-43454: This issue was addressed through improved state management. This issue is fixed in iOS 18.7.2 and iP This issue was addressed through improved state management. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. A device may persistently fail to lock.
nvd
CVE-2025-43449P3HIGHCVSS 7.5fixed in 26.12025-11-04
CVE-2025-43449 [HIGH] CWE-200 CVE-2025-43449: The issue was addressed with improved handling of caches. This issue is fixed in iOS 26.1 and iPadOS The issue was addressed with improved handling of caches. This issue is fixed in iOS 26.1 and iPadOS 26.1. A malicious app may be able to track users between installs.
nvd
CVE-2026-28929P3HIGHCVSS 7.5fixed in 18.7.92026-05-11
CVE-2026-28929 [HIGH] CWE-1254 CVE-2026-28929: A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7. A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. Replying to an email could display remote images in Mail in Lockdown Mode.
nvd
CVE-2026-28944P3HIGHCVSS 7.5fixed in 26.52026-05-11
CVE-2026-28944 [HIGH] CWE-119 CVE-2026-28944: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2025-43450P3HIGHCVSS 7.5fixed in 26.12025-11-04
CVE-2025-43450 [HIGH] CWE-284 CVE-2025-43450: A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7. A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An app may be able to learn information about the current camera view before being granted camera access.
nvd
CVE-2026-28964P3HIGHCVSS 7.5fixed in 26.52026-05-11
CVE-2026-28964 [HIGH] CWE-451 CVE-2026-28964: An inconsistent user interface issue was addressed with improved state management. This issue is fix An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 26.5 and iPadOS 26.5, visionOS 26.5. An app may be able to access sensitive user data.
nvd
CVE-2025-46311P3HIGHCVSS 7.5fixed in 18.7.3≥ 26.0, < 26.22026-05-12
CVE-2025-46311 [HIGH] CWE-451 CVE-2025-46311: An inconsistent user interface issue was addressed with improved state management. This issue is fix An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2. An app may be able to access sensitive user data.
nvd
CVE-2026-20649P3HIGHCVSS 7.5fixed in 26.32026-02-11
CVE-2026-20649 [HIGH] CWE-377 CVE-2026-20649: A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.3 and iPad A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, watchOS 26.3. A user may be able to view sensitive user information.
nvd
CVE-2026-43730P3CRITICALCVSS 9.8fixed in 26.62026-07-27
CVE-2026-43730 [CRITICAL] CWE-200 CVE-2026-43730: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to fingerprint the user.
nvd
CVE-2020-6514P3MEDIUMCVSS 6.5fixed in 13.62020-07-22
CVE-2020-6514 [MEDIUM] CWE-200 CVE-2020-6514: Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.
nvd
CVE-2026-64740P3CRITICALCVSS 9.3fixed in 26.62026-07-27
CVE-2026-64740 [CRITICAL] CWE-22 CVE-2026-64740: A parsing issue in the handling of directory paths was addressed with improved path validation. This A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6. A malicious app may be able to break out of its sandbox.
nvd
CVE-2020-9794P3HIGHCVSS 8.1fixed in 13.52020-06-09
CVE-2020-9794 [HIGH] CWE-125 CVE-2020-9794: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.5 a An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. A malicious application may cause a denial of service or potentially disclose memory contents.
nvd
Apple iPadOS vulnerabilities | cvebase