Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 154 of 207
CVE-2023-32424P4MEDIUMCVSS 5.5fixed in 16.42024-01-10
CVE-2023-32424 [MEDIUM] CVE-2023-32424: The issue was addressed with improved memory handling. This issue is fixed in iOS 16.4 and iPadOS 16
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.4 and iPadOS 16.4, watchOS 9.4. An attacker that has already achieved kernel code execution may be able to bypass kernel memory mitigations.
nvd
CVE-2025-43391P4MEDIUMCVSS 5.5fixed in 26.12025-11-04
CVE-2025-43391 [MEDIUM] CWE-200 CVE-2025-43391: A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.
nvd
CVE-2025-31212P4MEDIUMCVSS 5.5fixed in 18.52025-05-12
CVE-2025-31212 [MEDIUM] CWE-284 CVE-2025-31212: This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPad
This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. An app may be able to access sensitive user data.
nvd
CVE-2025-43498P4MEDIUMCVSS 5.5fixed in 26.12025-11-04
CVE-2025-43498 [MEDIUM] CWE-284 CVE-2025-43498: An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.1
An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, visionOS 26.1. An app may be able to access sensitive user data.
nvd
CVE-2024-44147P4MEDIUMCVSS 5.5fixed in 18.02024-09-17
CVE-2024-44147 [MEDIUM] CWE-269 CVE-2024-44147: This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS
This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. An app may gain unauthorized access to Local Network.
nvd
CVE-2026-20668P4MEDIUMCVSS 5.5fixed in 18.7.7≥ 26.0, < 26.32026-03-25
CVE-2026-20668 [MEDIUM] CWE-532 CVE-2026-20668: A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.7 and iP
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.3, visionOS 26.3. An app may be able to access sensitive user data.
nvd
CVE-2020-3869P4MEDIUMCVSS 5.3fixed in 13.3.12020-02-27
CVE-2020-3869 [MEDIUM] CVE-2020-3869: An issue existed in the handling of the local user's self-view. The issue was corrected with improve
An issue existed in the handling of the local user's self-view. The issue was corrected with improved logic. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1. A remote FaceTime user may be able to cause the local user's camera self-view to display the incorrect camera.
nvd
CVE-2025-46288P4MEDIUMCVSS 5.5fixed in 26.22025-12-17
CVE-2025-46288 [MEDIUM] CWE-284 CVE-2025-46288: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2. An app may be able to access sensitive payment tokens.
nvd
CVE-2026-20653P4MEDIUMCVSS 5.5fixed in 18.7.5≥ 26.0, < 26.32026-02-11
CVE-2026-20653 [MEDIUM] CWE-22 CVE-2026-20653: A parsing issue in the handling of directory paths was addressed with improved path validation. This
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. An app may be able to access sensitive user data.
nvd
CVE-2026-64722P4MEDIUMCVSS 5.5fixed in 26.62026-07-27
CVE-2026-64722 [MEDIUM] CWE-120 CVE-2026-64722: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 26.6
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a 3D model may result in disclosure of process memory.
nvd
CVE-2025-43345P4MEDIUMCVSS 5.5fixed in 18.72025-11-04
CVE-2025-43345 [MEDIUM] CWE-200 CVE-2025-43345: A correctness issue was addressed with improved checks. This issue is fixed in iOS 18.7 and iPadOS 1
A correctness issue was addressed with improved checks. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An app may be able to access sensitive user data.
nvd
CVE-2025-43360P4MEDIUMCVSS 5.5fixed in 26.02025-11-04
CVE-2025-43360 [MEDIUM] CWE-200 CVE-2025-43360: The issue was addressed with improved UI. This issue is fixed in iOS 26 and iPadOS 26. Password fiel
The issue was addressed with improved UI. This issue is fixed in iOS 26 and iPadOS 26. Password fields may be unintentionally revealed.
nvd
CVE-2026-20627P4MEDIUMCVSS 5.5fixed in 26.32026-02-11
CVE-2026-20627 [MEDIUM] CWE-20 CVE-2026-20627: An issue existed in the handling of environment variables. This issue was addressed with improved va
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3, watchOS 26.3. An app may be able to access sensitive user data.
nvd
CVE-2026-28958P4MEDIUMCVSS 5.5fixed in 26.52026-05-11
CVE-2026-28958 [MEDIUM] CWE-200 CVE-2026-28958: This issue was addressed with improved data protection. This issue is fixed in Safari 26.5, iOS 26.5
This issue was addressed with improved data protection. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. An app may be able to access sensitive user data.
nvd
CVE-2026-43800P4MEDIUMCVSS 5.5fixed in 26.62026-07-27
CVE-2026-43800 [MEDIUM] CWE-200 CVE-2026-43800: An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed i
An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.
nvd
CVE-2026-43796P4MEDIUMCVSS 5.5fixed in 26.62026-07-27
CVE-2026-43796 [MEDIUM] CWE-200 CVE-2026-43796: This issue was addressed with improved data protection. This issue is fixed in iOS 26.6 and iPadOS 2
This issue was addressed with improved data protection. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.
nvd
CVE-2026-64721P4MEDIUMCVSS 5.5fixed in 26.62026-07-27
CVE-2026-64721 [MEDIUM] CWE-664 CVE-2026-64721: This issue was addressed through improved state management. This issue is fixed in iOS 26.6 and iPad
This issue was addressed through improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.
nvd
CVE-2026-43801P4MEDIUMCVSS 5.5fixed in 26.62026-07-27
CVE-2026-43801 [MEDIUM] CWE-200 CVE-2026-43801: This issue was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macO
This issue was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.
nvd
CVE-2026-43714P4MEDIUMCVSS 5.5fixed in 26.62026-07-27
CVE-2026-43714 [MEDIUM] CWE-20 CVE-2026-43714: The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS
The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. A malicious app may be able to access protected user data.
nvd
CVE-2026-28988P4MEDIUMCVSS 5.5fixed in 26.52026-05-11
CVE-2026-28988 [MEDIUM] CWE-284 CVE-2026-28988: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, watchOS 26.5. An app may be able to bypass certain Privacy preferences.
nvd