Apple iPadOS vulnerabilities
1,835 known vulnerabilities affecting apple/ipados.
Total CVEs
1,835
CISA KEV
79
actively exploited
Public exploits
8
Exploited in wild
62
Severity breakdown
CRITICAL105HIGH806MEDIUM800LOW124
Vulnerabilities
Page 52 of 92
CVE-2022-32948HIGHCVSS 7.8fixed in 15.62022-12-15
CVE-2022-32948 [HIGH] CWE-125 CVE-2022-32948: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 15.6 a
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2022-42805HIGHCVSS 7.8fixed in 15.62022-12-15
CVE-2022-42805 [HIGH] CWE-190 CVE-2022-42805: An integer overflow was addressed with improved input validation. This issue is fixed in iOS 15.6 an
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2022-32860HIGHCVSS 7.8fixed in 15.62022-12-15
CVE-2022-32860 [HIGH] CWE-787 CVE-2022-32860: An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 15.6
An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, macOS Big Sur 11.6.8. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2022-42850HIGHCVSS 7.8fixed in 16.22022-12-15
CVE-2022-42850 [HIGH] CWE-787 CVE-2022-42850: The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2022-42864HIGHCVSS 7.0fixed in 15.7.2≥ 16.0, < 16.22022-12-15
CVE-2022-42864 [HIGH] CWE-362 CVE-2022-42864: A race condition was addressed with improved state handling. This issue is fixed in tvOS 16.2, macOS
A race condition was addressed with improved state handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2022-46693HIGHCVSS 7.8fixed in 16.22022-12-15
CVE-2022-46693 [HIGH] CWE-787 CVE-2022-46693: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in tv
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing a maliciously crafted file may lead to arbitrary code execution.
nvd
CVE-2022-46692MEDIUMCVSS 5.5fixed in 15.7.2≥ 16.0, < 16.22022-12-15
CVE-2022-46692 [MEDIUM] CWE-345 CVE-2022-46692: A logic issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS
A logic issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, iOS 15.7.2 and iPadOS 15.7.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may bypass Same Origin Policy.
nvd
CVE-2022-42866MEDIUMCVSS 5.5fixed in 16.22022-12-15
CVE-2022-42866 [MEDIUM] CWE-200 CVE-2022-42866: The issue was addressed with improved handling of caches. This issue is fixed in iOS 16.2 and iPadOS
The issue was addressed with improved handling of caches. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to read sensitive location information.
nvd
CVE-2022-42851MEDIUMCVSS 5.5fixed in 16.22022-12-15
CVE-2022-42851 [MEDIUM] CWE-125 CVE-2022-42851: The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, tvOS 16.2. Parsing a maliciously crafted TIFF file may lead to disclosure of user information.
nvd
CVE-2022-46695MEDIUMCVSS 6.5fixed in 15.7.2≥ 16.0, < 16.22022-12-15
CVE-2022-46695 [MEDIUM] CWE-1021 CVE-2022-46695: A spoofing issue existed in the handling of URLs. This issue was addressed with improved input valid
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Visiting a website that frames malicious content may lead to UI spoofing.
nvd
CVE-2022-42859MEDIUMCVSS 5.5fixed in 16.22022-12-15
CVE-2022-42859 [MEDIUM] CWE-284 CVE-2022-42859: Multiple issues were addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and
Multiple issues were addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, watchOS 9.2. An app may be able to bypass Privacy preferences.
nvd
CVE-2022-42865MEDIUMCVSS 5.5fixed in 16.22022-12-15
CVE-2022-42865 [MEDIUM] CWE-284 CVE-2022-42865: This issue was addressed by enabling hardened runtime. This issue is fixed in iOS 16.2 and iPadOS 16
This issue was addressed by enabling hardened runtime. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to bypass Privacy preferences.
nvd
CVE-2022-42846MEDIUMCVSS 5.5fixed in 15.7.2≥ 16.0, < 16.22022-12-15
CVE-2022-42846 [MEDIUM] CWE-119 CVE-2022-42846: The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS 15.7.2. Parsing a maliciously crafted video file may lead to unexpected system termination.
nvd
CVE-2022-42852MEDIUMCVSS 6.5fixed in 15.7.2≥ 16.0, < 16.22022-12-15
CVE-2022-42852 [MEDIUM] CWE-200 CVE-2022-42852: The issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2
The issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may result in the disclosure of process memory.
nvd
CVE-2022-32945MEDIUMCVSS 4.3fixed in 16.02022-12-15
CVE-2022-32945 [MEDIUM] CWE-284 CVE-2022-32945: An access issue was addressed with additional sandbox restrictions on third-party apps. This issue i
An access issue was addressed with additional sandbox restrictions on third-party apps. This issue is fixed in macOS Ventura 13. An app may be able to record audio with paired AirPods.
nvd
CVE-2022-42862MEDIUMCVSS 5.5fixed in 16.22022-12-15
CVE-2022-42862 [MEDIUM] CWE-284 CVE-2022-42862: This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and iPadOS
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. An app may be able to bypass Privacy preferences.
nvd
CVE-2022-32943MEDIUMCVSS 5.3fixed in 16.22022-12-15
CVE-2022-32943 [MEDIUM] CWE-125 CVE-2022-32943: The issue was addressed with improved bounds checks. This issue is fixed in iOS 16.2 and iPadOS 16.2
The issue was addressed with improved bounds checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Shake-to-undo may allow a deleted photo to be re-surfaced without authentication.
nvd
CVE-2022-42843MEDIUMCVSS 5.5fixed in 16.22022-12-15
CVE-2022-42843 [MEDIUM] CWE-200 CVE-2022-42843: This issue was addressed with improved data protection. This issue is fixed in iOS 16.2 and iPadOS 1
This issue was addressed with improved data protection. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. A user may be able to view sensitive user information.
nvd
CVE-2022-46702MEDIUMCVSS 5.5≥ 16.0, < 16.22022-12-15
CVE-2022-46702 [MEDIUM] CWE-200 CVE-2022-46702: The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2. An app may be able to disclose kernel memory.
nvd
CVE-2022-46698MEDIUMCVSS 6.5fixed in 16.22022-12-15
CVE-2022-46698 [MEDIUM] CWE-693 CVE-2022-46698: A logic issue was addressed with improved checks. This issue is fixed in Safari 16.2, tvOS 16.2, iCl
A logic issue was addressed with improved checks. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may disclose sensitive user information.
nvd