VYPR

iOS and iPadOS

by Apple Inc.

CVEs (905)

  • CVE-2024-40852MedSep 17, 2024
    risk 0.34cvss 5.3epss 0.00

    This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18 and iPadOS 18. An attacker may be able to see recent photos without authentication in Assistive Access.

  • CVE-2023-42836MedFeb 21, 2024
    risk 0.34cvss 5.3epss 0.01

    A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, macOS Ventura 13.6.3, macOS Sonoma 14.1, macOS Monterey 12.7.2. An attacker may be able to access connected network volumes mounted in the home directory.

  • CVE-2023-34352MedSep 6, 2023
    risk 0.34cvss 5.3epss 0.01

    A permissions issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Ventura 13.4, tvOS 16.5, iOS 16.5 and iPadOS 16.5, watchOS 9.5. An attacker may be able to leak user account emails.

  • CVE-2023-23494MedMay 8, 2023
    risk 0.34cvss 5.3epss 0.01

    A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 16.4 and iPadOS 16.4. A user in a privileged network position may be able to cause a denial-of-service.

  • CVE-2021-1837MedSep 8, 2021
    risk 0.34cvss 5.3epss 0.00

    A certificate validation issue was addressed. This issue is fixed in iOS 14.5 and iPadOS 14.5. An attacker in a privileged network position may be able to alter network traffic.

  • CVE-2021-30998MedAug 24, 2021
    risk 0.34cvss 5.3epss 0.01

    A S/MIME issue existed in the handling of encrypted email. This issue was addressed with improved selection of the encryption certificate. This issue is fixed in iOS 15.2 and iPadOS 15.2. A sender's email address may be leaked when sending an S/MIME encrypted email using a…

  • CVE-2025-30434MedMar 31, 2025
    risk 0.33cvss 5.0epss 0.00

    The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.4 and iPadOS 18.4. Processing a maliciously crafted file may lead to a cross site scripting attack.

  • CVE-2021-1865MedSep 8, 2021
    risk 0.33cvss 5.0epss 0.01

    An issue obscuring passwords in screenshots was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14.5. A user's password may be visible on screen.

  • CVE-2025-43541MedDec 17, 2025
    risk 0.31cvss 4.3epss 0.34

    A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.

  • CVE-2023-42941MedJan 10, 2024
    risk 0.31cvss 4.8epss 0.00

    The issue was addressed with improved checks. This issue is fixed in iOS 17.2 and iPadOS 17.2. An attacker in a privileged network position may be able to perform a denial-of-service attack using crafted Bluetooth packets.

  • CVE-2022-32919MedJan 10, 2024
    risk 0.31cvss 4.7epss 0.01

    The issue was addressed with improved UI handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Visiting a website that frames malicious content may lead to UI spoofing.

  • CVE-2021-30884MedAug 24, 2021
    risk 0.31cvss 4.7epss 0.01

    The issue was resolved with additional restrictions on CSS compositing. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Visiting a maliciously crafted website may reveal a user's browsing history.

  • CVE-2026-28895MedMar 25, 2026
    risk 0.30cvss 4.6epss 0.00

    The issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. An attacker with physical access to an iOS device with Stolen Device Protection enabled may be able to access biometrics-gated Protected Apps with the passcode.

  • CVE-2026-28856MedMar 25, 2026
    risk 0.30cvss 4.6epss 0.00

    The issue was addressed with improved authentication. This issue is fixed in iOS 26.4 and iPadOS 26.4, visionOS 26.4, watchOS 26.4. An attacker with physical access to a locked device may be able to view sensitive user information.

  • CVE-2026-20674MedFeb 11, 2026
    risk 0.30cvss 4.6epss 0.00

    A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.

  • CVE-2026-20640MedFeb 11, 2026
    risk 0.30cvss 4.6epss 0.00

    An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3. An attacker with physical access to iPhone may be able to take and view screenshots of sensitive data from the iPhone during iPhone Mirroring with…

  • CVE-2025-43418MedNov 5, 2025
    risk 0.30cvss 4.6epss 0.00

    This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An attacker with physical access to a locked device may be able to view sensitive user information.

  • CVE-2025-43460MedNov 4, 2025
    risk 0.30cvss 4.6epss 0.00

    A logic issue was addressed with improved checks. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker with physical access to a locked device may be able to view sensitive user information.

  • CVE-2025-43452MedNov 4, 2025
    risk 0.30cvss 4.6epss 0.00

    This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 26.1 and iPadOS 26.1. Keyboard suggestions may display sensitive information on the lock screen.

  • CVE-2025-43422MedNov 4, 2025
    risk 0.30cvss 4.6epss 0.00

    The issue was addressed by adding additional logic. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker with physical access to a device may be able to disable Stolen Device Protection.

Page 39 of 46