Apple visionOS vulnerabilities

410 known vulnerabilities affecting apple/visionos.

Total CVEs
410
CISA KEV
17
actively exploited
Public exploits
1
Exploited in wild
6
Severity breakdown
CRITICAL30HIGH122MEDIUM248LOW10

Vulnerabilities

Page 19 of 21
CVE-2024-40789MEDIUMCVSS 6.5fixed in 1.32024-07-29
CVE-2024-40789 [MEDIUM] CWE-125 CVE-2024-40789: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Sa An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
cvelistv5nvd
CVE-2024-40782MEDIUMCVSS 6.5fixed in 1.32024-07-29
CVE-2024-40782 [MEDIUM] CWE-416 CVE-2024-40782: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
cvelistv5nvd
CVE-2024-27863MEDIUMCVSS 5.5fixed in 1.32024-07-29
CVE-2024-27863 [MEDIUM] CVE-2024-27863: An information disclosure issue was addressed with improved private data redaction for log entries. An information disclosure issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. A local attacker may be able to determine kernel memory layout.
cvelistv5nvd
CVE-2024-40780MEDIUMCVSS 5.5fixed in 1.32024-07-29
CVE-2024-40780 [MEDIUM] CWE-125 CVE-2024-40780: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17. An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
cvelistv5nvd
CVE-2024-40779MEDIUMCVSS 5.5fixed in 1.32024-07-29
CVE-2024-40779 [MEDIUM] CWE-125 CVE-2024-40779: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17. An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
cvelistv5nvd
CVE-2024-40788MEDIUMCVSS 5.5fixed in 1.32024-07-29
CVE-2024-40788 [MEDIUM] CWE-843 CVE-2024-40788: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 16.7. A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, visionOS 1.3, watchOS 10.6. A local attacker may be able to cause unexpected system shutdown.
cvelistv5nvd
CVE-2024-27884MEDIUMCVSS 5.5fixed in 1.22024-07-29
CVE-2024-27884 [MEDIUM] CWE-200 CVE-2024-27884: This issue was addressed with a new entitlement. This issue is fixed in iOS 17.5 and iPadOS 17.5, ma This issue was addressed with a new entitlement. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. An app may be able to access user-sensitive data.
cvelistv5nvd
CVE-2024-27823MEDIUMCVSS 5.9fixed in 1.32024-07-29
CVE-2024-27823 [MEDIUM] CWE-362 CVE-2024-27823: A race condition was addressed with improved locking. This issue is fixed in iOS 16.7.8 and iPadOS 1 A race condition was addressed with improved locking. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.3, watchOS 10.5. An attacker in a privileged network position may be able to spoof network packets.
cvelistv5nvd
CVE-2024-40785MEDIUMCVSS 6.1fixed in 1.32024-07-29
CVE-2024-40785 [MEDIUM] CWE-79 CVE-2024-40785: This issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 16.7.9 and iP This issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to a cross site scripting attack.
cvelistv5nvd
CVE-2024-40776MEDIUMCVSS 4.3fixed in 1.32024-07-29
CVE-2024-40776 [MEDIUM] CWE-416 CVE-2024-40776: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
cvelistv5nvd
CVE-2024-27811HIGHCVSS 7.8fixed in 1.22024-06-10
CVE-2024-27811 [HIGH] CWE-269 CVE-2024-27811: The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. An app may be able to elevate privileges.
cvelistv5nvd
CVE-2024-27817HIGHCVSS 7.8fixed in 1.22024-06-10
CVE-2024-27817 [HIGH] CWE-353 CVE-2024-27817: The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, i The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.2. An app may be able to execute arbitrary code with kernel privileges.
cvelistv5nvd
CVE-2024-27851HIGHCVSS 8.8fixed in 1.22024-06-10
CVE-2024-27851 [HIGH] CWE-119 CVE-2024-27851: The issue was addressed with improved bounds checks. This issue is fixed in Safari 17.5, iOS 17.5 an The issue was addressed with improved bounds checks. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing maliciously crafted web content may lead to arbitrary code execution.
cvelistv5nvd
CVE-2024-27828HIGHCVSS 7.8fixed in 1.22024-06-10
CVE-2024-27828 [HIGH] CWE-786 CVE-2024-27828: The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17 The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. An app may be able to execute arbitrary code with kernel privileges.
cvelistv5nvd
CVE-2024-27857HIGHCVSS 7.8fixed in 1.22024-06-10
CVE-2024-27857 [HIGH] CWE-119 CVE-2024-27857: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2. A remote attacker may be able to cause unexpected app termination or arbitrary code execution.
cvelistv5nvd
CVE-2024-27802HIGHCVSS 7.8fixed in 1.22024-06-10
CVE-2024-27802 [HIGH] CWE-125 CVE-2024-27802: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 16.7. An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
cvelistv5nvd
CVE-2024-27808HIGHCVSS 8.8fixed in 1.22024-06-10
CVE-2024-27808 [HIGH] CWE-786 CVE-2024-27808: The issue was addressed with improved memory handling. This issue is fixed in Safari 17.5, iOS 17.5 The issue was addressed with improved memory handling. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing web content may lead to arbitrary code execution.
cvelistv5nvd
CVE-2024-27833HIGHCVSS 8.8fixed in 1.22024-06-10
CVE-2024-27833 [HIGH] CWE-190 CVE-2024-27833: An integer overflow was addressed with improved input validation. This issue is fixed in Safari 17.5 An integer overflow was addressed with improved input validation. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, tvOS 17.5, visionOS 1.2. Processing maliciously crafted web content may lead to arbitrary code execution.
cvelistv5nvd
CVE-2024-27836HIGHCVSS 7.8fixed in 1.22024-06-10
CVE-2024-27836 [HIGH] CWE-787 CVE-2024-27836: The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, visionOS 1.2. Processing a maliciously crafted image may lead to arbitrary code execution.
cvelistv5nvd
CVE-2024-27815HIGHCVSS 7.8fixed in 1.22024-06-10
CVE-2024-27815 [HIGH] CWE-787 CVE-2024-27815: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iO An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. An app may be able to execute arbitrary code with kernel privileges.
cvelistv5nvd