Apple visionOS vulnerabilities
410 known vulnerabilities affecting apple/visionos.
Total CVEs
410
CISA KEV
17
actively exploited
Public exploits
1
Exploited in wild
6
Severity breakdown
CRITICAL30HIGH122MEDIUM248LOW10
Vulnerabilities
Page 21 of 21
CVE-2024-23284MEDIUMCVSS 6.5fixed in 1.12024-03-08
CVE-2024-23284 [MEDIUM] CWE-693 CVE-2024-23284: A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS
A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
cvelistv5nvd
CVE-2024-23254MEDIUMCVSS 6.5fixed in 1.12024-03-08
CVE-2024-23254 [MEDIUM] CVE-2024-23254: The issue was addressed with improved UI handling. This issue is fixed in Safari 17.4, iOS 17.4 and
The issue was addressed with improved UI handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. A malicious website may exfiltrate audio data cross-origin.
cvelistv5nvd
CVE-2024-23264MEDIUMCVSS 5.5fixed in 1.12024-03-08
CVE-2024-23264 [MEDIUM] CWE-125 CVE-2024-23264: A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 16.7.6
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1. An application may be able to read restricted memory.
cvelistv5nvd
CVE-2024-23295MEDIUMCVSS 5.5fixed in 1.12024-03-08
CVE-2024-23295 [MEDIUM] CWE-276 CVE-2024-23295: A permissions issue was addressed to help ensure Personas are always protected. This issue is fixed
A permissions issue was addressed to help ensure Personas are always protected. This issue is fixed in visionOS 1.1. An unauthenticated user may be able to use an unprotected Persona.
cvelistv5nvd
CVE-2024-23262LOWCVSS 3.3fixed in 1.12024-03-08
CVE-2024-23262 [LOW] CWE-863 CVE-2024-23262: This issue was addressed with additional entitlement checks. This issue is fixed in iOS 16.7.6 and i
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, visionOS 1.1. An app may be able to spoof system notifications and UI.
cvelistv5nvd
CVE-2024-23257LOWCVSS 3.3fixed in 1.12024-03-08
CVE-2024-23257 [LOW] CWE-119 CVE-2024-23257: The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.6 and iPadOS
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, visionOS 1.1. Processing an image may result in disclosure of process memory.
cvelistv5nvd
CVE-2024-23225HIGHCVSS 7.8KEVfixed in 1.12024-03-05
CVE-2024-23225 [HIGH] CWE-787 CVE-2024-23225: A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protection
cvelistv5nvd
CVE-2024-23296HIGHCVSS 7.8KEVfixed in 1.12024-03-05
CVE-2024-23296 [HIGH] CWE-787 CVE-2024-23296: A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.7, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protection
cvelistv5nvd
CVE-2024-1580HIGHCVSS 8.8fixed in 1.1.12024-02-19
CVE-2024-1580 [HIGH] CWE-190 CVE-2024-1580: An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size.
An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.
nvd
CVE-2024-23222HIGHCVSS 8.8KEVfixed in 1.0.22024-01-23
CVE-2024-23222 [HIGH] CWE-843 CVE-2024-23222: A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 1
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, visionOS 1.0.2. Processing maliciously crafted web content may lead to arbitrary code execution.
cvelistv5nvd
← Previous21 / 21