cbcvebase.

Apple visionOS vulnerabilities

475 known vulnerabilities affecting apple/visionos.

Total CVEs
475
CISA KEV
17
actively exploited
Public exploits
2
Exploited in wild
6
Severity breakdown
CRITICAL30HIGH160MEDIUM273LOW12

Vulnerabilities

Page 4 of 24
CVE-2026-28886MEDIUMCVSS 5.9fixed in 26.42026-03-25
CVE-2026-28886 [MEDIUM] CWE-476 CVE-2026-28886: A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. A user in a privileged network position may be able to cause a denial-of-service.
nvd
CVE-2026-28868MEDIUMCVSS 5.5fixed in 26.42026-03-25
CVE-2026-28868 [MEDIUM] CWE-532 CVE-2026-28868: A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.7 and iP A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. An app may be able to disclose kernel memory.
nvd
CVE-2026-20657MEDIUMCVSS 6.5fixed in 26.42026-03-25
CVE-2026-20657 [MEDIUM] CWE-119 CVE-2026-20657: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 18.7 A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4. Parsing a maliciously crafted file may lead to an unexpected app termination.
nvd
CVE-2026-28856MEDIUMCVSS 4.6fixed in 26.42026-03-25
CVE-2026-28856 [MEDIUM] CWE-284 CVE-2026-28856: The issue was addressed with improved authentication. This issue is fixed in iOS 26.4 and iPadOS 26. The issue was addressed with improved authentication. This issue is fixed in iOS 26.4 and iPadOS 26.4, visionOS 26.4, watchOS 26.4. An attacker with physical access to a locked device may be able to view sensitive user information.
nvd
CVE-2026-20691MEDIUMCVSS 4.3fixed in 26.42026-03-25
CVE-2026-20691 [MEDIUM] CWE-497 CVE-2026-20691: An authorization issue was addressed with improved state management. This issue is fixed in Safari 2 An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. A maliciously crafted webpage may be able to fingerprint the user.
nvd
CVE-2026-20664MEDIUMCVSS 4.3fixed in 26.42026-03-25
CVE-2026-20664 [MEDIUM] CWE-787 CVE-2026-20664: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-28863MEDIUMCVSS 6.5fixed in 26.42026-03-25
CVE-2026-28863 [MEDIUM] CWE-284 CVE-2026-28863: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.4 and A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.4 and iPadOS 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to fingerprint the user.
nvd
CVE-2026-28822MEDIUMCVSS 6.2fixed in 26.42026-03-25
CVE-2026-28822 [MEDIUM] CWE-843 CVE-2026-28822: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An attacker may be able to cause unexpected app termination.
nvd
CVE-2026-20637MEDIUMCVSS 6.2fixed in 26.32026-03-25
CVE-2026-20637 [MEDIUM] CWE-416 CVE-2026-20637: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18. A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to cause unexpected system termination.
nvdapple
CVE-2026-28852MEDIUMCVSS 5.5fixed in 26.42026-03-25
CVE-2026-28852 [MEDIUM] CWE-20 CVE-2026-28852: A stack overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and A stack overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to cause a denial-of-service.
nvd
CVE-2026-28857MEDIUMCVSS 6.5fixed in 26.42026-03-25
CVE-2026-28857 [MEDIUM] CWE-125 CVE-2026-28857: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-20665MEDIUMCVSS 6.5fixed in 26.42026-03-25
CVE-2026-20665 [MEDIUM] CWE-693 CVE-2026-20665: This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
nvd
CVE-2026-28882MEDIUMCVSS 4.0fixed in 26.42026-03-25
CVE-2026-28882 [MEDIUM] CVE-2026-28882: This issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, This issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to enumerate a user's installed apps.
nvd
CVE-2026-28879MEDIUMCVSS 6.5fixed in 26.42026-03-25
CVE-2026-28879 [MEDIUM] CWE-416 CVE-2026-28879: A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18. A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-28867MEDIUMCVSS 6.2fixed in 26.42026-03-25
CVE-2026-28867 [MEDIUM] CVE-2026-28867: This issue was addressed with improved authentication. This issue is fixed in iOS 18.7.7 and iPadOS This issue was addressed with improved authentication. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to leak sensitive kernel state.
nvd
CVE-2026-28870MEDIUMCVSS 5.5fixed in 26.42026-03-25
CVE-2026-28870 [MEDIUM] CVE-2026-28870: An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.9 a An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to access sensitive user data.
nvd
CVE-2026-28877MEDIUMCVSS 5.5fixed in 26.42026-03-25
CVE-2026-28877 [MEDIUM] CWE-200 CVE-2026-28877: An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7 An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. An app may be able to access sensitive user data.
nvd
CVE-2026-28878MEDIUMCVSS 6.5fixed in 26.42026-03-25
CVE-2026-28878 [MEDIUM] CWE-200 CVE-2026-28878: A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.7.7 and iPad A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.7, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to enumerate a user's installed apps.
nvd
CVE-2026-28864LOWCVSS 3.3fixed in 26.42026-03-25
CVE-2026-28864 [LOW] CWE-863 CVE-2026-28864: This issue was addressed with improved permissions checking. This issue is fixed in iOS 18.7.7 and i This issue was addressed with improved permissions checking. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. A local attacker may gain access to user's Keychain items.
nvd
CVE-2026-20643MEDIUMCVSS 5.4fixed in 26.42026-03-17
CVE-2026-20643 [MEDIUM] CWE-20 CVE-2026-20643: A cross-origin issue in the Navigation API was addressed with improved input validation. This issue A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS, iPadOS, and macOS, Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may bypass Same Origin Policy.
nvd