VYPR

Ipados

by Apple Inc.

CVEs (1,423)

  • CVE-2025-24202Mar 31, 2025
    risk 0.00cvss epss 0.00

    A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.

  • CVE-2025-24208Mar 31, 2025
    risk 0.00cvss epss 0.01

    A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4. Loading a malicious iframe may lead to a cross-site scripting attack.

  • CVE-2025-30469Mar 31, 2025
    risk 0.00cvss epss 0.00

    This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4. A person with physical access to an iOS device may be able to access photos from the lock screen.

  • CVE-2025-30428Mar 31, 2025
    risk 0.00cvss epss 0.00

    This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6. Photos in the Hidden Photos Album may be viewed without authentication.

  • CVE-2024-44276Mar 17, 2025
    risk 0.00cvss epss 0.00

    This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.2 and iPadOS 18.2. A user in a privileged network position may be able to leak sensitive information.

  • CVE-2024-54558Mar 10, 2025
    risk 0.00cvss epss 0.00

    A clickjacking issue was addressed with improved out-of-process view handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to trick a user into granting access to photos from the user's photo library.

  • CVE-2025-24141Jan 27, 2025
    risk 0.00cvss epss 0.00

    An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3. An attacker with physical access to an unlocked device may be able to access Photos while the app is locked.

  • CVE-2025-24102Jan 27, 2025
    risk 0.00cvss epss 0.01

    The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to determine a user’s current location.

  • CVE-2024-40839Jan 15, 2025
    risk 0.00cvss epss 0.00

    This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to an iOS device may be able to view notification contents from the Lock Screen.

  • CVE-2024-44136Jan 15, 2025
    risk 0.00cvss epss 0.00

    This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to a device may be able to disable Stolen Device Protection.

  • CVE-2024-54503Dec 11, 2024
    risk 0.00cvss epss 0.00

    An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.2 and iPadOS 18.2. Muting a call while ringing may not result in mute being enabled.

  • CVE-2024-44261Oct 28, 2024
    risk 0.00cvss epss 0.00

    This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1. An attacker may be able to view restricted content from the lock screen.

  • CVE-2024-44251Oct 28, 2024
    risk 0.00cvss epss 0.00

    This issue was addressed through improved state management. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to view restricted content from the lock screen.

  • CVE-2024-40851Oct 28, 2024
    risk 0.00cvss epss 0.00

    This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker with physical access may be able to access contact photos from the lock screen.

  • CVE-2024-40867Oct 28, 2024
    risk 0.00cvss epss 0.01

    A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in iOS 18.1 and iPadOS 18.1. A remote attacker may be able to break out of Web Content sandbox.

  • CVE-2024-44204Oct 3, 2024
    risk 0.00cvss epss 0.05

    A logic issue was addressed with improved validation. This issue is fixed in iOS 18.0.1 and iPadOS 18.0.1. A user's saved passwords may be read aloud by VoiceOver.

  • CVE-2024-44124Sep 16, 2024
    risk 0.00cvss epss 0.00

    This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. A malicious Bluetooth input device may bypass pairing.

  • CVE-2024-40852Sep 16, 2024
    risk 0.00cvss epss 0.00

    This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18 and iPadOS 18. An attacker may be able to see recent photos without authentication in Assistive Access.

  • CVE-2024-44180Sep 16, 2024
    risk 0.00cvss epss 0.00

    The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical access may be able to access contacts from the lock screen.

  • CVE-2024-44139Sep 16, 2024
    risk 0.00cvss epss 0.00

    The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical access may be able to access contacts from the lock screen.