Apple
28,601 known vulnerabilities
Top Products
The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryp
A remote attacker can supply a short X-Wing HPKE encapsulated key and trigger an out-of-bounds read in the C decapsulati
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a malicious
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.6. An app may be ab
An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonom
A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Son
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a malicious
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18
This issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 1
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1. A malicious application may be
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. A malicious a
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be
A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.1. An app may be able
CocoaMQTT is a MQTT 5.0 client library for iOS and macOS written in Swift. Prior to version 2.2.2, a vulnerability exist
Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of
Inappropriate implementation in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain poten
Use after free in Compositing in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the
Use after free in Navigation in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the
Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker who had compromi
Use after free in PDF in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code insid
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via
Use after free in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code ins
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the render
Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to leak cross-o
Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the render
Use after free in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code
Object corruption in V8 in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code ins
Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbi
Integer overflow in ANGLE in Google Chrome on Windows prior to 146.0.7680.178 allowed a remote attacker who had compromi
Insufficient policy enforcement in WebUSB in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain p
Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 146.0.7680.178 allowed a remote attacker to execute arbit
Integer overflow in Codecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform arbitrary read/
Use after free in CSS in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code insid
Heap buffer overflow in GPU in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code
The application's list box calculate array logic keeps stale references to page or form objects after they are deleted o
The application does not detect or guard against cyclic PDF object references while handling JavaScript in PDF. When pag
The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript ch
The application does not validate the presence of required appearance (AP) data before accessing stamp annotation resour
Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbi
Gematik Authenticator securely authenticates users for login to digital health applications. Starting in version 4.12.0
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is vulnera
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could prov
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is affecte
The issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. An attacker with physical
A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 26.4 and iPadOS 26.4,
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Tahoe 26.4. A docu
A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.5, macOS So
Frequently Asked Questions
How many CVEs affect Apple?
Apple has 28,601 CVE records in our database, including 1791 critical and 14441 high severity vulnerabilities. 117 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Apple vulnerabilities?
Apple has 1791 critical severity (CVSS 9.0+) and 14441 high severity (CVSS 7.0-8.9) vulnerabilities. 117 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Apple vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Apple products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Apple Vulnerabilities
CyberStrike scans your infrastructure for Apple vulnerabilities and provides real-time remediation guidance.
Get Started