Apple Vulnerabilities
Apple builds the iPhone, iPad, Mac and Apple Watch and their operating systems: iOS, iPadOS, macOS and watchOS. The database tracks 95 Apple CVE records. CISA lists 95 of them as exploited in the wild, most recently on 2026-09-29. The most affected products are iOS, iPadOS, and macOS, iOS, macOS.
Recently Exploited Apple CVEs
Apple Multiple Products Out-of-Bounds Write Vulnerability
Apple macOS Improper Authentication Vulnerability
Apple Multiple Products Buffer Overflow Vulnerability
Apple Multiple Products Classic Buffer Overflow Vulnerability
Apple Multiple Products Improper Locking Vulnerability
Apple Multiple Products Integer Overflow or Wraparound Vulnerability
Affected Products
9 products| Product | CVEs | KEV | Latest |
|---|---|---|---|
| Multiple Products | 54 | 54 | 2026-09-29 |
| iOS, iPadOS, and macOS | 11 | 11 | 2025-08-21 |
| iOS | 8 | 8 | 2022-12-14 |
| macOS | 6 | 6 | 2026-08-18 |
| iOS and iPadOS | 5 | 5 | 2026-03-05 |
| iOS and macOS | 4 | 4 | 2022-08-18 |
| iOS, iPadOS, and watchOS | 4 | 4 | 2023-09-11 |
| OS X | 2 | 2 | 2022-02-10 |
| iOS, macOS, watchOS | 1 | 1 | 2022-08-25 |
Security Advisories
All Apple CVEs
95 records| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-86950 | Apple Multiple Products Out-of-Bounds Write Vulnerability | Apple | 8.8 | 1.2% | KEV | 2026-09-28 |
| CVE-2026-65400 | Apple macOS Improper Authentication Vulnerability | Apple | 9.8 | 1.7% | KEV | 2026-08-06 |
| CVE-2025-31277 | Apple Multiple Products Buffer Overflow Vulnerability | Apple | 8.8 | 1.6% | KEV | 2025-07-29 |
| CVE-2025-43520 | Apple Multiple Products Classic Buffer Overflow Vulnerability | Apple | 5.5 | 0.4% | KEV | 2025-12-12 |
| CVE-2025-43510 | Apple Multiple Products Improper Locking Vulnerability | Apple | 7.8 | 0.4% | KEV | 2025-12-12 |
| CVE-2021-30952 | Apple Multiple Products Integer Overflow or Wraparound Vulnerability | Apple | 8.8 | 7.0% | KEV | 2021-08-24 |
| CVE-2023-43000 | Apple Multiple products Use-After-Free Vulnerability | Apple | 8.8 | 4.0% | KEV | 2025-11-05 |
| CVE-2023-41974 | Apple iOS and iPadOS Use-After-Free Vulnerability | Apple | 7.8 | 2.0% | KEV | 2024-01-10 |
| CVE-2026-20700 | Apple Multiple Buffer Overflow Vulnerability | Apple | 7.8 | 1.4% | KEV | 2026-02-11 |
| CVE-2025-43529 | Apple Multiple Products Use-After-Free WebKit Vulnerability | Apple | 8.8 | 8.8% | KEV | 2025-12-17 |
| CVE-2022-48503 | Apple Multiple Products Unspecified Vulnerability | Apple | 8.8 | 3.2% | KEV | 2023-08-14 |
| CVE-2025-43300 | Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability | Apple | 10.0 | 32.5% | KEV | 2025-08-21 |
| CVE-2025-43200 | Apple Multiple Products Unspecified Vulnerability | Apple | 4.2 | 1.2% | KEV | 2025-06-16 |
| CVE-2025-31200 | Apple Multiple Products Memory Corruption Vulnerability | Apple | 9.8 | 18.8% | KEV | 2025-04-16 |
| CVE-2025-31201 | Apple Multiple Products Arbitrary Read and Write Vulnerability | Apple | 9.8 | 14.0% | KEV | 2025-04-16 |
| CVE-2025-24201 | Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability | Apple | 10.0 | 3.8% | KEV | 2025-03-11 |
| CVE-2025-24200 | Apple iOS and iPadOS Incorrect Authorization Vulnerability | Apple | 6.1 | 4.4% | KEV | 2025-02-10 |
| CVE-2025-24085 | Apple Multiple Products Use-After-Free Vulnerability | Apple | 10.0 | 17.5% | KEV | 2025-01-27 |
| CVE-2024-44309 | Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability | Apple | 6.3 | 22.6% | KEV | 2024-11-19 |
| CVE-2024-44308 | Apple Multiple Products Code Execution Vulnerability | Apple | 8.8 | 10.2% | KEV | 2024-11-19 |
| CVE-2024-23225 | Apple Multiple Products Memory Corruption Vulnerability | Apple | 7.8 | 1.5% | KEV | 2024-03-05 |
| CVE-2024-23296 | Apple Multiple Products Memory Corruption Vulnerability | Apple | 7.8 | 1.4% | KEV | 2024-03-05 |
| CVE-2022-48618 | Apple Multiple Products Memory Corruption Vulnerability | Apple | 7.0 | 0.5% | KEV | 2024-01-09 |
| CVE-2024-23222 | Apple Multiple Products WebKit Type Confusion Vulnerability | Apple | 8.8 | 10.6% | KEV | 2024-01-23 |
| CVE-2023-41990 | Apple Multiple Products Code Execution Vulnerability | Apple | 7.8 | 1.4% | KEV | 2023-09-11 |
| CVE-2023-42916 | Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability | Apple | 6.5 | 17.8% | KEV | 2023-11-30 |
| CVE-2023-42917 | Apple Multiple Products WebKit Memory Corruption Vulnerability | Apple | 8.8 | 9.3% | KEV | 2023-11-30 |
| CVE-2023-42824 | Apple iOS and iPadOS Kernel Privilege Escalation Vulnerability | Apple | 7.8 | 1.1% | KEV | 2023-10-04 |
| CVE-2023-41993 | Apple Multiple Products WebKit Code Execution Vulnerability | Apple | 8.8 | 24.3% | KEV | 2023-09-21 |
| CVE-2023-41991 | Apple Multiple Products Improper Certificate Validation Vulnerability | Apple | 5.5 | 13.4% | KEV | 2023-09-21 |
| CVE-2023-41992 | Apple Multiple Products Kernel Privilege Escalation Vulnerability | Apple | 7.8 | 9.5% | KEV | 2023-09-21 |
| CVE-2023-41064 | Apple iOS, iPadOS, and macOS ImageIO Buffer Overflow Vulnerability | Apple | 7.8 | 53.4% | KEV | 2023-09-07 |
| CVE-2023-41061 | Apple iOS, iPadOS, and watchOS Wallet Code Execution Vulnerability | Apple | 7.8 | 4.4% | KEV | 2023-09-07 |
| CVE-2023-38606 | Apple Multiple Products Kernel Unspecified Vulnerability | Apple | 5.5 | 2.9% | KEV | 2023-07-26 |
| CVE-2023-37450 | Apple Multiple Products WebKit Code Execution Vulnerability | Apple | 8.8 | 18.9% | KEV | 2023-07-26 |
| CVE-2023-32434 | Apple Multiple Products Integer Overflow Vulnerability | Apple | 7.8 | 51.5% | KEV | 2023-06-23 |
| CVE-2023-32439 | Apple Multiple Products WebKit Type Confusion Vulnerability | Apple | 8.8 | 24.0% | KEV | 2023-06-23 |
| CVE-2023-32435 | Apple Multiple Products WebKit Memory Corruption Vulnerability | Apple | 8.8 | 23.0% | KEV | 2023-06-23 |
| CVE-2023-32409 | Apple Multiple Products WebKit Sandbox Escape Vulnerability | Apple | 8.6 | 16.5% | KEV | 2023-06-23 |
| CVE-2023-28204 | Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability | Apple | 6.5 | 14.3% | KEV | 2023-06-23 |
| CVE-2023-32373 | Apple Multiple Products WebKit Use-After-Free Vulnerability | Apple | 8.8 | 12.2% | KEV | 2023-06-23 |
| CVE-2019-8526 | Apple macOS Use-After-Free Vulnerability | Apple | 7.8 | 0.7% | KEV | 2019-12-18 |
| CVE-2023-28205 | Apple Multiple Products WebKit Use-After-Free Vulnerability | Apple | 8.8 | 27.1% | KEV | 2023-04-10 |
| CVE-2023-28206 | Apple iOS, iPadOS, and macOS IOSurfaceAccelerator Out-of-Bounds Write Vulnerability | Apple | 8.6 | 23.2% | KEV | 2023-04-10 |
| CVE-2021-30900 | Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability | Apple | 7.8 | 5.2% | KEV | 2021-08-24 |
| CVE-2023-23529 | Apple Multiple Products WebKit Type Confusion Vulnerability | Apple | 8.8 | 9.5% | KEV | 2023-02-27 |
| CVE-2022-42856 | Apple iOS Type Confusion Vulnerability | Apple | 8.8 | 8.5% | KEV | 2022-12-15 |
| CVE-2022-42827 | Apple iOS and iPadOS Out-of-Bounds Write Vulnerability | Apple | 7.8 | 1.1% | KEV | 2022-11-01 |
| CVE-2022-32917 | Apple iOS, iPadOS, and macOS Remote Code Execution Vulnerability | Apple | 7.8 | 5.6% | KEV | 2022-09-20 |
| CVE-2020-9934 | Apple iOS, iPadOS, and macOS Input Validation Vulnerability | Apple | 5.5 | 3.2% | KEV | 2020-10-16 |
| CVE-2021-31010 | Apple iOS, macOS, watchOS Sandbox Bypass Vulnerability | Apple | 7.5 | 3.7% | KEV | 2021-08-24 |
| CVE-2022-32893 | Apple iOS and macOS Out-of-Bounds Write Vulnerability | Apple | 8.8 | 9.9% | KEV | 2022-08-24 |
| CVE-2022-32894 | Apple iOS and macOS Out-of-Bounds Write Vulnerability | Apple | 7.8 | 3.3% | KEV | 2022-08-24 |
| CVE-2019-8605 | Apple Multiple Products Use-After-Free Vulnerability | Apple | 7.8 | 17.6% | KEV | 2019-12-18 |
| CVE-2020-3837 | Apple Multiple Products Memory Corruption Vulnerability | Apple | 7.8 | 14.8% | KEV | 2020-02-27 |
| CVE-2020-9907 | Apple Multiple Products Memory Corruption Vulnerability | Apple | 7.8 | 3.2% | KEV | 2020-10-16 |
| CVE-2021-30983 | Apple iOS and iPadOS Buffer Overflow Vulnerability | Apple | 7.8 | 2.9% | KEV | 2021-08-24 |
| CVE-2018-4344 | Apple Multiple Products Memory Corruption Vulnerability | - | 7.8 | 2.4% | KEV | 2019-04-03 |
| CVE-2016-4657 | Apple iOS Webkit Memory Corruption Vulnerability | - | 8.8 | 66.8% | KEV | 2016-08-25 |
| CVE-2016-4655 | Apple iOS Information Disclosure Vulnerability | - | 5.5 | 33.4% | KEV | 2016-08-25 |
| CVE-2016-4656 | Apple iOS Memory Corruption Vulnerability | - | 7.8 | 23.6% | KEV | 2016-08-25 |
| CVE-2019-7286 | Apple Multiple Products Memory Corruption Vulnerability | Apple | 7.8 | 15.9% | KEV | 2019-12-18 |
| CVE-2021-30883 | Apple Multiple Products Memory Corruption Vulnerability | Apple | 7.8 | 14.7% | KEV | 2021-08-24 |
| CVE-2019-7287 | Apple iOS Memory Corruption Vulnerability | Apple | 7.8 | 4.6% | KEV | 2019-12-18 |
| CVE-2019-8506 | Apple Multiple Products Type Confusion Vulnerability | Apple | 8.8 | 16.2% | KEV | 2019-12-18 |
| CVE-2021-1789 | Apple Multiple Products Type Confusion Vulnerability | Apple | 8.8 | 14.0% | KEV | 2021-04-02 |
| CVE-2022-22675 | Apple macOS Out-of-Bounds Write Vulnerability | Apple | 7.8 | 12.5% | KEV | 2022-05-26 |
| CVE-2022-22674 | Apple macOS Out-of-Bounds Read Vulnerability | Apple | 5.5 | 1.1% | KEV | 2022-05-26 |
| CVE-2022-22620 | Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability | Apple | 8.8 | 16.3% | KEV | 2022-03-18 |
| CVE-2014-4404 | Apple OS X Heap-Based Buffer Overflow Vulnerability | - | 7.8 | 48.9% | KEV | 2014-09-18 |
| CVE-2015-1130 | Apple OS X Authentication Bypass Vulnerability | - | 7.8 | 9.9% | KEV | 2015-04-10 |
| CVE-2022-22587 | Apple Memory Corruption Vulnerability | Apple | 9.8 | 11.6% | KEV | 2022-03-18 |
| CVE-2021-30860 | Apple Multiple Products Integer Overflow Vulnerability | Apple | 7.8 | 76.0% | KEV | 2021-08-24 |
| CVE-2021-30657 | Apple macOS Unspecified Vulnerability | Apple | 5.5 | 68.5% | KEV | 2021-09-08 |
| CVE-2021-30807 | Apple Multiple Products Memory Corruption Vulnerability | Apple | 7.8 | 28.8% | KEV | 2021-10-19 |
| CVE-2020-27930 | Apple Multiple Products Memory Corruption Vulnerability | Apple | 7.8 | 22.0% | KEV | 2020-12-08 |
| CVE-2020-27950 | Apple Multiple Products Memory Initialization Vulnerability | Apple | 5.5 | 16.5% | KEV | 2020-12-08 |
| CVE-2021-30858 | Apple iOS, iPadOS, macOS Use-After-Free Vulnerability | Apple | 8.8 | 13.4% | KEV | 2021-08-24 |
| CVE-2021-30762 | Apple iOS WebKit Use-After-Free Vulnerability | Apple | 8.8 | 11.0% | KEV | 2021-09-08 |
| CVE-2021-30761 | Apple iOS WebKit Memory Corruption Vulnerability | Apple | 8.8 | 10.5% | KEV | 2021-09-08 |
| CVE-2020-27932 | Apple Multiple Products Type Confusion Vulnerability | Apple | 7.8 | 10.3% | KEV | 2020-12-08 |
| CVE-2021-1870 | Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability | Apple | 9.8 | 7.7% | KEV | 2021-04-02 |
| CVE-2021-1879 | Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability | Apple | 6.1 | 7.1% | KEV | 2021-04-02 |
| CVE-2021-30713 | Apple macOS Unspecified Vulnerability | Apple | 7.8 | 7.0% | KEV | 2021-09-08 |
| CVE-2021-1871 | Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability | Apple | 9.8 | 7.0% | KEV | 2021-04-02 |
| CVE-2021-30661 | Apple Multiple Products WebKit Storage Use-After-Free Vulnerability | Apple | 8.8 | 4.5% | KEV | 2021-09-08 |
| CVE-2021-30869 | Apple iOS, iPadOS, and macOS Type Confusion Vulnerability | Apple | 7.8 | 4.1% | KEV | 2021-08-24 |
| CVE-2021-30665 | Apple Multiple Products WebKit Memory Corruption Vulnerability | Apple | 8.8 | 3.7% | KEV | 2021-09-08 |
| CVE-2021-30663 | Apple Multiple Products WebKit Integer Overflow Vulnerability | Apple | 7.8 | 3.5% | KEV | 2021-09-08 |
| CVE-2021-30666 | Apple iOS WebKit Buffer Overflow Vulnerability | Apple | 8.8 | 3.0% | KEV | 2021-09-08 |
| CVE-2019-6223 | Apple iOS and macOS Group Facetime Vulnerability | Apple | 7.5 | 2.6% | KEV | 2019-03-05 |
| CVE-2020-9818 | Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability | Apple | 8.8 | 2.3% | KEV | 2020-06-09 |
| CVE-2021-1782 | Apple Multiple Products Race Condition Vulnerability | Apple | 7.0 | 2.2% | KEV | 2021-04-02 |
| CVE-2020-9819 | Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability | Apple | 4.3 | 2.2% | KEV | 2020-06-09 |
| CVE-2020-9859 | Apple Multiple Products Code Execution Vulnerability | Apple | 7.8 | 0.8% | KEV | 2020-06-05 |
Frequently Asked Questions
How many Apple vulnerabilities are actively exploited?→
95 Apple CVEs are in the CISA Known Exploited Vulnerabilities catalog as of 2026-10-09. The latest was added on 2026-09-29.
Which Apple products have the most exploited vulnerabilities?→
- +Multiple Products: 54 CVEs (54 in KEV)
- +iOS, iPadOS, and macOS: 11 CVEs (11 in KEV)
- +iOS: 8 CVEs (8 in KEV)
- +macOS: 6 CVEs (6 in KEV)
- +iOS and iPadOS: 5 CVEs (5 in KEV)
Where does Apple publish security advisories?→
Apple publishes security advisories at https://support.apple.com/en-us/100100. Check the vendor advisory for fixed versions and workarounds before applying updates.
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Vendor and product names for exploited CVEs follow the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not affiliated with or endorsed by Apple, MITRE, CISA, or FIRST.