Apple visionOS vulnerabilities

410 known vulnerabilities affecting apple/visionos.

Total CVEs
410
CISA KEV
17
actively exploited
Public exploits
1
Exploited in wild
6
Severity breakdown
CRITICAL30HIGH122MEDIUM248LOW10

Vulnerabilities

Page 20 of 21
CVE-2024-27820HIGHCVSS 8.8fixed in 1.22024-06-10
CVE-2024-27820 [HIGH] CWE-119 CVE-2024-27820: The issue was addressed with improved memory handling. This issue is fixed in Safari 17.5, iOS 16.7. The issue was addressed with improved memory handling. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing web content may lead to arbitrary code execution.
cvelistv5nvd
CVE-2024-27801HIGHCVSS 7.8fixed in 1.22024-06-10
CVE-2024-27801 [HIGH] CVE-2024-27801: The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. An app may be able to elevate privileges.
cvelistv5nvd
CVE-2024-27831HIGHCVSS 7.8fixed in 1.22024-06-10
CVE-2024-27831 [HIGH] CWE-787 CVE-2024-27831: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iO An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.2. Processing a file may lead to unexpected app termination or arbitrary code execution.
cvelistv5nvd
CVE-2024-27832HIGHCVSS 7.8fixed in 1.22024-06-10
CVE-2024-27832 [HIGH] CWE-703 CVE-2024-27832: The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. An app may be able to elevate privileges.
cvelistv5nvd
CVE-2024-27800MEDIUMCVSS 6.5fixed in 1.22024-06-10
CVE-2024-27800 [MEDIUM] CWE-400 CVE-2024-27800: This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.8 and iPad This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing a maliciously crafted message may lead to a denial-of-service.
cvelistv5nvd
CVE-2024-27850MEDIUMCVSS 6.5fixed in 1.22024-06-10
CVE-2024-27850 [MEDIUM] CWE-359 CVE-2024-27850: This issue was addressed with improvements to the noise injection algorithm. This issue is fixed in This issue was addressed with improvements to the noise injection algorithm. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, visionOS 1.2. A maliciously crafted webpage may be able to fingerprint the user.
cvelistv5nvd
CVE-2024-27812MEDIUMCVSS 6.5fixed in 1.22024-06-10
CVE-2024-27812 [MEDIUM] CWE-400 CVE-2024-27812: A logic issue was addressed with improved file handling. This issue is fixed in visionOS 1.2. Proces A logic issue was addressed with improved file handling. This issue is fixed in visionOS 1.2. Processing web content may lead to a denial-of-service.
cvelistv5nvd
CVE-2024-27838MEDIUMCVSS 6.5fixed in 1.22024-06-10
CVE-2024-27838 [MEDIUM] CWE-79 CVE-2024-27838: The issue was addressed by adding additional logic. This issue is fixed in Safari 17.5, iOS 16.7.8 a The issue was addressed by adding additional logic. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. A maliciously crafted webpage may be able to fingerprint the user.
cvelistv5nvd
CVE-2024-27830MEDIUMCVSS 6.5fixed in 1.22024-06-10
CVE-2024-27830 [MEDIUM] CVE-2024-27830: This issue was addressed through improved state management. This issue is fixed in Safari 17.5, iOS This issue was addressed through improved state management. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. A maliciously crafted webpage may be able to fingerprint the user.
cvelistv5nvd
CVE-2024-27840MEDIUMCVSS 6.3fixed in 1.22024-06-10
CVE-2024-27840 [MEDIUM] CWE-786 CVE-2024-27840: The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.2, watchOS 10.5. An attacker that has already achieved kernel code execution may be able to bypass kernel memory protections.
cvelistv5nvd
CVE-2024-27844MEDIUMCVSS 5.5fixed in 1.22024-06-10
CVE-2024-27844 [MEDIUM] CVE-2024-27844: The issue was addressed with improved checks. This issue is fixed in Safari 17.5, macOS Sonoma 14.5, The issue was addressed with improved checks. This issue is fixed in Safari 17.5, macOS Sonoma 14.5, visionOS 1.2. A website's permission dialog may persist after navigation away from the site.
cvelistv5nvd
CVE-2024-27804MEDIUMCVSS 5.5fixed in 1.3v1.32024-05-14
CVE-2024-27804 [MEDIUM] CWE-770 CVE-2024-27804: The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17 The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.3, watchOS 10.5. An app may be able to cause unexpected system termination.
cvelistv5nvd
CVE-2024-23286HIGHCVSS 7.8fixed in 1.12024-03-08
CVE-2024-23286 [HIGH] CWE-120 CVE-2024-23286: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.7 A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing an image may lead to arbitrary code execution.
cvelistv5nvd
CVE-2024-23258HIGHCVSS 7.8fixed in 1.12024-03-08
CVE-2024-23258 [HIGH] CWE-125 CVE-2024-23258: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Son An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.4, visionOS 1.1. Processing an image may lead to arbitrary code execution.
cvelistv5nvd
CVE-2024-23265HIGHCVSS 7.8fixed in 1.12024-03-08
CVE-2024-23265 [HIGH] CWE-787 CVE-2024-23265: A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 16 A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watchOS 10.4. An app may be able to cause unexpected system termination or write kernel memory.
cvelistv5nvd
CVE-2024-23226HIGHCVSS 8.8fixed in 1.12024-03-08
CVE-2024-23226 [HIGH] CWE-787 CVE-2024-23226: The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17 The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing web content may lead to arbitrary code execution.
cvelistv5nvd
CVE-2024-23246HIGHCVSS 8.6fixed in 1.12024-03-08
CVE-2024-23246 [HIGH] CWE-20 CVE-2024-23246: This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.6 and iPad This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. An app may be able to break out of its sandbox.
cvelistv5nvd
CVE-2024-23220MEDIUMCVSS 5.5fixed in 1.12024-03-08
CVE-2024-23220 [MEDIUM] CVE-2024-23220: The issue was addressed with improved handling of caches. This issue is fixed in iOS 17.4 and iPadOS The issue was addressed with improved handling of caches. This issue is fixed in iOS 17.4 and iPadOS 17.4, visionOS 1.1. An app may be able to fingerprint the user.
cvelistv5nvd
CVE-2024-23263MEDIUMCVSS 6.5fixed in 1.12024-03-08
CVE-2024-23263 [MEDIUM] CWE-20 CVE-2024-23263: A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
cvelistv5nvd
CVE-2024-23235MEDIUMCVSS 4.7fixed in 1.12024-03-08
CVE-2024-23235 [MEDIUM] CWE-362 CVE-2024-23235: A race condition was addressed with additional validation. This issue is fixed in iOS 16.7.6 and iPa A race condition was addressed with additional validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. An app may be able to access user-sensitive data.
cvelistv5nvd