cbcvebase.

Apple visionOS vulnerabilities

475 known vulnerabilities affecting apple/visionos.

Total CVEs
475
CISA KEV
17
actively exploited
Public exploits
2
Exploited in wild
6
Severity breakdown
CRITICAL30HIGH160MEDIUM273LOW12

Vulnerabilities

Page 16 of 24
CVE-2025-30432MEDIUMCVSS 6.4fixed in 2.42025-03-31
CVE-2025-30432 [MEDIUM] CWE-287 CVE-2025-30432: A logic issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPad A logic issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. A malicious app may be able to attempt passcode entries on a locked device and thereby cause escalating time delays after 4 failures.
nvdapple
CVE-2025-24216MEDIUMCVSS 4.3fixed in 2.42025-03-31
CVE-2025-24216 [MEDIUM] CWE-119 CVE-2025-24216: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
CVE-2025-24194MEDIUMCVSS 6.5fixed in 2.42025-03-31
CVE-2025-24194 [MEDIUM] CVE-2025-24194: A logic issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, m A logic issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may result in the disclosure of process memory.
nvdapple
CVE-2025-24192MEDIUMCVSS 6.5fixed in 2.42025-03-31
CVE-2025-24192 [MEDIUM] CVE-2025-24192: A script imports issue was addressed with improved isolation. This issue is fixed in Safari 18.4, iO A script imports issue was addressed with improved isolation. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4. Visiting a website may leak sensitive data.
nvdapple
CVE-2025-24182MEDIUMCVSS 5.5fixed in 2.42025-03-31
CVE-2025-24182 [MEDIUM] CWE-125 CVE-2025-24182: An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing a maliciously crafted font may result in the disclosure of process memory.
nvdapple
CVE-2025-24203MEDIUMCVSS 5.0fixed in 2.42025-03-31
CVE-2025-24203 [MEDIUM] CVE-2025-24203: The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadO The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to modify protected parts of the file system.
nvdapple
CVE-2025-24212MEDIUMCVSS 6.3fixed in 2.42025-03-31
CVE-2025-24212 [MEDIUM] CVE-2025-24212: This issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPad This issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to break out of its sandbox.
nvdapple
CVE-2025-30427MEDIUMCVSS 4.3fixed in 2.42025-03-31
CVE-2025-30427 [MEDIUM] CWE-416 CVE-2025-30427: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
CVE-2025-30429MEDIUMCVSS 6.3fixed in 2.42025-03-31
CVE-2025-30429 [MEDIUM] CVE-2025-30429: A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.4 and iP A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to break out of its sandbox.
nvdapple
CVE-2025-30470MEDIUMCVSS 5.5fixed in 2.42025-03-31
CVE-2025-30470 [MEDIUM] CWE-22 CVE-2025-30470: A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.4 and iPadOS A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, visionOS 2.4, watchOS 11.4. An app may be able to read sensitive location information.
nvdapple
CVE-2025-24210MEDIUMCVSS 5.5fixed in 2.42025-03-31
CVE-2025-24210 [MEDIUM] CWE-783 CVE-2025-24210: A logic error was addressed with improved error handling. This issue is fixed in iOS 18.4 and iPadOS A logic error was addressed with improved error handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. Parsing an image may lead to disclosure of user information.
nvdapple
CVE-2025-24214MEDIUMCVSS 5.5fixed in 2.42025-03-31
CVE-2025-24214 [MEDIUM] CWE-284 CVE-2025-24214: A privacy issue was addressed by not logging contents of text fields. This issue is fixed in iOS 18. A privacy issue was addressed by not logging contents of text fields. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to access sensitive user data.
nvdapple
CVE-2025-24283MEDIUMCVSS 5.5fixed in 2.42025-03-31
CVE-2025-24283 [MEDIUM] CWE-200 CVE-2025-24283: A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPad A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. An app may be able to access sensitive user data.
nvdapple
CVE-2025-30439MEDIUMCVSS 4.6fixed in 2.42025-03-31
CVE-2025-30439 [MEDIUM] CWE-200 CVE-2025-30439: The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. An attacker with physical access to a locked device may be able to view sensitive user information.
nvdapple
CVE-2024-9681MEDIUMCVSS 6.5v2.42025-03-31
CVE-2024-9681 [MEDIUM] CVE-2024-9681: visionOS 2.4 Apple Security Update: About the security content of visionOS 2.4 Product: visionOS Version: 2.4 CVE: CVE-2024-9681 Component: CVE-2024-9681
apple
CVE-2025-30447MEDIUMCVSS 5.5fixed in 2.42025-03-31
CVE-2025-30447 [MEDIUM] CWE-200 CVE-2025-30447: The issue was resolved by sanitizing logging. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadO The issue was resolved by sanitizing logging. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to access sensitive user data.
nvdapple
CVE-2025-27113LOWCVSS 2.9v2.42025-03-31
CVE-2025-27113 [LOW] CVE-2025-27113: visionOS 2.4 Apple Security Update: About the security content of visionOS 2.4 Product: visionOS Version: 2.4 CVE: CVE-2025-27113 Component: CVE-2025-27113
apple
CVE-2024-54551HIGHCVSS 7.5fixed in 1.32025-03-21
CVE-2024-54551 [HIGH] CWE-119 CVE-2024-54551: The issue was addressed with improved memory handling. This issue is fixed in Safari 17.6, iOS 17.6 The issue was addressed with improved memory handling. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing web content may lead to a denial-of-service.
nvdapple
CVE-2024-54564MEDIUMCVSS 6.5fixed in 1.32025-03-21
CVE-2024-54564 [MEDIUM] CWE-276 CVE-2024-54564: This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPad This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, visionOS 1.3. A file received from AirDrop may not have the quarantine flag applied.
nvdapple
CVE-2024-54525HIGHCVSS 8.8fixed in 2.22025-03-17
CVE-2024-54525 [HIGH] CWE-434 CVE-2024-54525: A logic issue was addressed with improved file handling. This issue is fixed in iOS 18.2 and iPadOS A logic issue was addressed with improved file handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Restoring a maliciously crafted backup file may lead to modification of protected system files.
nvd
Apple visionOS vulnerabilities | cvebase