Apple visionOS vulnerabilities

410 known vulnerabilities affecting apple/visionos.

Total CVEs
410
CISA KEV
17
actively exploited
Public exploits
1
Exploited in wild
6
Severity breakdown
CRITICAL30HIGH122MEDIUM248LOW10

Vulnerabilities

Page 18 of 21
CVE-2024-27880MEDIUMCVSS 5.5fixed in 2.0fixed in 22024-09-17
CVE-2024-27880 [MEDIUM] CWE-125 CVE-2024-27880: An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, tvOS 18, visionOS 2, watchOS 11. Processing a maliciously crafted file may lead to unexpected app termination.
cvelistv5nvd
CVE-2024-44176MEDIUMCVSS 5.5fixed in 2.0fixed in 22024-09-17
CVE-2024-44176 [MEDIUM] CWE-400 CVE-2024-44176: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7, tvOS 18, visionOS 2, watchOS 11. Processing an image may lead to a denial-of-service.
cvelistv5nvd
CVE-2024-40857MEDIUMCVSS 6.1fixed in 2.0fixed in 22024-09-17
CVE-2024-40857 [MEDIUM] CWE-79 CVE-2024-40857: This issue was addressed through improved state management. This issue is fixed in Safari 18, iOS 18 This issue was addressed through improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. Processing maliciously crafted web content may lead to universal cross site scripting.
cvelistv5nvd
CVE-2024-44198MEDIUMCVSS 5.5fixed in 2.0fixed in 22024-09-17
CVE-2024-44198 [MEDIUM] CWE-190 CVE-2024-44198: An integer overflow was addressed through improved input validation. This issue is fixed in iOS 18 a An integer overflow was addressed through improved input validation. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. Processing maliciously crafted web content may lead to an unexpected process crash.
cvelistv5nvd
CVE-2024-44183MEDIUMCVSS 5.5fixed in 2.0fixed in 22024-09-17
CVE-2024-44183 [MEDIUM] CWE-400 CVE-2024-44183: A logic error was addressed with improved error handling. This issue is fixed in iOS 17.7 and iPadOS A logic error was addressed with improved error handling. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7, tvOS 18, visionOS 2, watchOS 11. An app may be able to cause a denial-of-service.
cvelistv5nvd
CVE-2024-40850MEDIUMCVSS 5.5fixed in 2.0fixed in 22024-09-17
CVE-2024-40850 [MEDIUM] CWE-200 CVE-2024-40850: A file access issue was addressed with improved input validation. This issue is fixed in iOS 17.7 an A file access issue was addressed with improved input validation. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7, tvOS 18, visionOS 2, watchOS 11. An app may be able to access user-sensitive data.
cvelistv5nvd
CVE-2024-44187MEDIUMCVSS 6.5fixed in 2.0fixed in 22024-09-17
CVE-2024-44187 [MEDIUM] CWE-346 CVE-2024-44187: A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of se A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. A malicious website may exfiltrate data cross-origin.
cvelistv5nvd
CVE-2024-44169MEDIUMCVSS 5.5fixed in 2.0fixed in 22024-09-17
CVE-2024-44169 [MEDIUM] CWE-400 CVE-2024-44169: The issue was addressed with improved memory handling. This issue is fixed in iOS 17.7 and iPadOS 17 The issue was addressed with improved memory handling. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7, tvOS 18, visionOS 2, watchOS 11. An app may be able to cause unexpected system termination.
cvelistv5nvd
CVE-2024-44191MEDIUMCVSS 5.5fixed in 2.0fixed in 22024-09-17
CVE-2024-44191 [MEDIUM] CVE-2024-44191: This issue was addressed through improved state management. This issue is fixed in Xcode 16, iOS 17. This issue was addressed through improved state management. This issue is fixed in Xcode 16, iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. An app may gain unauthorized access to Bluetooth.
cvelistv5nvd
CVE-2024-44167MEDIUMCVSS 5.5fixed in 2.0fixed in 22024-09-17
CVE-2024-44167 [MEDIUM] CWE-22 CVE-2024-44167: This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18 and iPadOS 1 This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7, visionOS 2. An app may be able to overwrite arbitrary files.
cvelistv5nvd
CVE-2024-27876MEDIUMCVSS 5.5fixed in 2.0fixed in 22024-09-17
CVE-2024-27876 [MEDIUM] CWE-362 CVE-2024-27876: A race condition was addressed with improved locking. This issue is fixed in iOS 17.7 and iPadOS 17. A race condition was addressed with improved locking. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7, visionOS 2. Unpacking a maliciously crafted archive may allow an attacker to write arbitrary files.
cvelistv5nvd
CVE-2024-40825MEDIUMCVSS 4.4fixed in 2.0fixed in 22024-09-17
CVE-2024-40825 [MEDIUM] CWE-284 CVE-2024-40825: The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15, visionOS 2. A The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15, visionOS 2. A malicious app with root privileges may be able to modify the contents of system files.
cvelistv5nvd
CVE-2024-40865MEDIUMCVSS 5.3fixed in 1.32024-09-06
CVE-2024-40865 [MEDIUM] CVE-2024-40865: The issue was addressed by suspending Persona when the virtual keyboard is active. This issue is fix The issue was addressed by suspending Persona when the virtual keyboard is active. This issue is fixed in visionOS 1.3. Inputs to the virtual keyboard may be inferred from Persona.
cvelistv5nvd
CVE-2024-27826HIGHCVSS 7.8fixed in 1.32024-07-29
CVE-2024-27826 [HIGH] CWE-269 CVE-2024-27826: The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17 The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.6, macOS Sonoma 14.5, macOS Ventura 13.6.8, tvOS 17.5, visionOS 1.3, watchOS 10.5. A local attacker may be able to cause unexpected system shutdown.
cvelistv5nvd
CVE-2024-40809HIGHCVSS 7.8fixed in 1.32024-07-29
CVE-2024-40809 [HIGH] CVE-2024-40809: A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7. A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, visionOS 1.3, watchOS 10.6. A shortcut may be able to bypass Internet permission requirements.
cvelistv5nvd
CVE-2024-40799HIGHCVSS 7.1fixed in 1.32024-07-29
CVE-2024-40799 [HIGH] CWE-125 CVE-2024-40799: An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing a maliciously crafted file may lead to unexpected app termination.
cvelistv5nvd
CVE-2024-40812HIGHCVSS 7.8fixed in 1.32024-07-29
CVE-2024-40812 [HIGH] CWE-284 CVE-2024-40812: A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7. A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, visionOS 1.3, watchOS 10.6. A shortcut may be able to bypass Internet permission requirements.
cvelistv5nvd
CVE-2024-40777MEDIUMCVSS 5.5fixed in 1.32024-07-29
CVE-2024-40777 [MEDIUM] CWE-787 CVE-2024-40777: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing a maliciously crafted file may lead to unexpected app termination.
cvelistv5nvd
CVE-2024-40806MEDIUMCVSS 5.5fixed in 1.32024-07-29
CVE-2024-40806 [MEDIUM] CWE-125 CVE-2024-40806: An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing a maliciously crafted file may lead to unexpected app termination.
cvelistv5nvd
CVE-2024-40784MEDIUMCVSS 5.5fixed in 1.32024-07-29
CVE-2024-40784 [MEDIUM] CWE-190 CVE-2024-40784: An integer overflow was addressed with improved input validation. This issue is fixed in iOS 16.7.9 An integer overflow was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing a maliciously crafted file may lead to unexpected app termination.
cvelistv5nvd