Apple iPadOS vulnerabilities
2,029 known vulnerabilities affecting apple/ipados.
Total CVEs
2,029
CISA KEV
79
actively exploited
Public exploits
36
Exploited in wild
111
Severity breakdown
CRITICAL132HIGH884MEDIUM888LOW125
Vulnerabilities
Page 94 of 102
CVE-2025-43418P4MEDIUMCVSS 4.6fixed in 18.7.22025-11-05
CVE-2025-43418 [MEDIUM] CWE-284 CVE-2025-43418: This issue was addressed by restricting options offered on a locked device. This issue is fixed in i
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An attacker with physical access to a locked device may be able to view sensitive user information.
nvd
CVE-2026-20661P4MEDIUMCVSS 4.6fixed in 18.7.5≥ 26.0, < 26.32026-02-11
CVE-2026-20661 [MEDIUM] CWE-285 CVE-2026-20661: An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.
nvd
CVE-2026-20645P4MEDIUMCVSS 4.6fixed in 18.7.5≥ 26.0, < 26.32026-02-11
CVE-2026-20645 [MEDIUM] CWE-1021 CVE-2026-20645: An inconsistent user interface issue was addressed with improved state management. This issue is fix
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.
nvd
CVE-2026-20674P4MEDIUMCVSS 4.6fixed in 26.32026-02-11
CVE-2026-20674 [MEDIUM] CWE-200 CVE-2026-20674: A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.3 and iPadOS
A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.
nvd
CVE-2021-1854P4MEDIUMCVSS 4.3fixed in 14.52021-09-08
CVE-2021-1854 [MEDIUM] CWE-863 CVE-2021-1854: A call termination issue with was addressed with improved logic. This issue is fixed in iOS 14.5 and
A call termination issue with was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14.5. A legacy cellular network can automatically answer an incoming call when an ongoing call ends or drops. .
nvd
CVE-2023-41977P4MEDIUMCVSS 4.3fixed in 16.7.22023-10-25
CVE-2023-41977 [MEDIUM] CVE-2023-41977: The issue was addressed with improved handling of caches. This issue is fixed in macOS Sonoma 14.1,
The issue was addressed with improved handling of caches. This issue is fixed in macOS Sonoma 14.1, iOS 16.7.2 and iPadOS 16.7.2. Visiting a malicious website may reveal browsing history.
nvd
CVE-2022-22677P4MEDIUMCVSS 4.3fixed in 15.52022-11-01
CVE-2022-22677 [MEDIUM] CVE-2022-22677: A logic issue in the handling of concurrent media was addressed with improved state handling. This i
A logic issue in the handling of concurrent media was addressed with improved state handling. This issue is fixed in macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. Video self-preview in a webRTC call may be interrupted if the user answers a phone call.
nvd
CVE-2022-46725P4MEDIUMCVSS 4.3fixed in 16.42023-08-14
CVE-2022-46725 [MEDIUM] CVE-2022-46725: A spoofing issue existed in the handling of URLs. This issue was addressed with improved input valid
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.4 and iPadOS 16.4. Visiting a malicious website may lead to address bar spoofing.
nvd
CVE-2025-24128P4MEDIUMCVSS 4.3fixed in 18.32025-01-27
CVE-2025-24128 [MEDIUM] CVE-2025-24128: The issue was addressed by adding additional logic. This issue is fixed in Safari 18.3, iOS 18.3 and
The issue was addressed by adding additional logic. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. Visiting a malicious website may lead to address bar spoofing.
nvd
CVE-2024-27807P4MEDIUMCVSS 4.3fixed in 16.7.8≥ 17.0, < 17.52024-06-10
CVE-2024-27807 [MEDIUM] CVE-2024-27807: The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, i
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5. An app may be able to circumvent App Privacy Report logging.
nvd
CVE-2022-32781P4MEDIUMCVSS 4.4fixed in 15.52022-09-23
CVE-2022-32781 [MEDIUM] CWE-269 CVE-2022-32781: This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4, i
This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5, Security Update 2022-005 Catalina, macOS Big Sur 11.6.8. An app with root privileges may be able to access private information.
nvd
CVE-2021-30810P4MEDIUMCVSS 4.3fixed in 15.02021-10-19
CVE-2021-30810 [MEDIUM] CWE-862 CVE-2021-30810: An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 a
An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15, watchOS 8, tvOS 15. An attacker in physical proximity may be able to force a user onto a malicious Wi-Fi network during device setup.
nvd
CVE-2022-32857P4MEDIUMCVSS 4.3fixed in 15.62022-08-24
CVE-2022-32857 [MEDIUM] CWE-319 CVE-2022-32857: This issue was addressed by using HTTPS when sending information over the network. This issue is fix
This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6, tvOS 15.6, watchOS 8.7. A user in a privileged network position can track a user’s activity.
nvd
CVE-2025-43374P4MEDIUMCVSS 4.3fixed in 17.7.7≥ 18.0, < 18.52025-11-21
CVE-2025-43374 [MEDIUM] CWE-121 CVE-2025-43374: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 a
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.5, visionOS 2.5, watchOS 11.5. An attacker in physical proximity may be able to cause an out-of-bounds read in kernel memory.
nvdapple
CVE-2025-46286P4MEDIUMCVSS 4.3fixed in 26.22026-01-09
CVE-2025-46286 [MEDIUM] CWE-288 CVE-2025-46286: A logic issue was addressed with improved validation. This issue is fixed in iOS 26.2 and iPadOS 26.
A logic issue was addressed with improved validation. This issue is fixed in iOS 26.2 and iPadOS 26.2. Restoring from a backup may prevent passcode from being required immediately after Face ID enrollment.
nvd
CVE-2025-43265P4MEDIUMCVSS 4.0fixed in 18.62025-07-30
CVE-2025-43265 [MEDIUM] CWE-125 CVE-2025-43265: An out-of-bounds read was addressed with improved input validation. This issue is fixed in Safari 18
An out-of-bounds read was addressed with improved input validation. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may disclose internal states of the app.
nvd
CVE-2023-42941P4MEDIUMCVSS 4.8fixed in 17.22024-01-10
CVE-2023-42941 [MEDIUM] CWE-400 CVE-2023-42941: The issue was addressed with improved checks. This issue is fixed in iOS 17.2 and iPadOS 17.2. An at
The issue was addressed with improved checks. This issue is fixed in iOS 17.2 and iPadOS 17.2. An attacker in a privileged network position may be able to perform a denial-of-service attack using crafted Bluetooth packets.
nvd
CVE-2026-43743P4MEDIUMCVSS 4.7fixed in 26.5.22026-06-29
CVE-2026-43743 [MEDIUM] CWE-362 CVE-2026-43743: A race condition was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and i
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
nvd
CVE-2022-32935P4MEDIUMCVSS 4.6fixed in 15.7.12022-11-01
CVE-2022-32935 [MEDIUM] CWE-287 CVE-2022-32935: A lock screen issue was addressed with improved state management. This issue is fixed in iOS 15.7.1
A lock screen issue was addressed with improved state management. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16, macOS Ventura 13. A user may be able to view restricted content from the lock screen.
nvd
CVE-2023-32391P4MEDIUMCVSS 4.6fixed in 15.7.6≥ 16.0, < 16.52023-06-23
CVE-2023-32391 [MEDIUM] CWE-125 CVE-2023-32391: The issue was addressed with improved checks. This issue is fixed in iOS 15.7.6 and iPadOS 15.7.6, w
The issue was addressed with improved checks. This issue is fixed in iOS 15.7.6 and iPadOS 15.7.6, watchOS 9.5, iOS 16.5 and iPadOS 16.5, macOS Ventura 13.4. A shortcut may be able to use sensitive data with certain actions without prompting the user.
nvd