Apple
28,601 known vulnerabilities
Top Products
After Effects versions 25.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file,
After Effects versions 25.6 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could resul
After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary co
After Effects versions 25.6 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory ex
After Effects versions 25.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitr
Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network.
OpenClaw is a personal AI assistant. Prior to version 2026.1.29, there is an OS command injection vulnerability via the
Type Confusion in V8 in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corr
Heap buffer overflow in libvpx in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit
During the installation of the Native Access application, a privileged helper `com.native-instruments.NativeAccess.Helpe
Umbraco Forms is a form builder that integrates with the Umbraco content management system. It's possible for an authent
An out-of-bounds read was addressed with improved input validation. This issue is fixed in Pages 15.1, iOS 26.1 and iPad
The issue was addressed with improved bounds checks. This issue is fixed in Keynote 15.1, iOS 26 and iPadOS 26, macOS Ta
The ArchiveReader.extractContents() function used by cctl image load and container image load performs no pathname valid
Use after free in ANGLE in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit heap co
Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoo
Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the content
Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559.59 allowed an attack who obtained a netw
Incorrect security UI in Digital Credentials in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perfor
Inappropriate implementation in Downloads in Google Chrome on Windows prior to 144.0.7559.59 allowed a remote attacker t
Inappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform an out o
Inappropriate implementation in Blink in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to pe
Inappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially expl
Out of bounds memory access in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially explo
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able
A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. An app may be able to
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app
This issue was addressed through improved state management. This issue is fixed in iOS 18.1 and iPadOS 18.1. A user may
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1
This issue was addressed with improved permissions checking. This issue is fixed in macOS Sequoia 15.1. An app may be ab
Owlfiles File Manager 12.0.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious scr
Owlfiles File Manager 12.0.1 contains a path traversal vulnerability in its built-in HTTP server that allows attackers t
Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free vulnerability that could result in arbi
InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could
Illustrator versions 29.8.3, 30.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead t
Bridge versions 15.1.2, 16.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in
InCopy versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in
Illustrator versions 29.8.3, 30.0 and earlier are affected by an Untrusted Search Path vulnerability that could result i
InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Out-of-bounds Read vulnerability that could lead t
InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could
InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that
InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that
Dreamweaver Desktop versions 21.6 and earlier are affected by an Incorrect Authorization vulnerability that could result
Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could lead
Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could resu
Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could resu
Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Neutralization of Special Elements used in an
A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, mac
Frequently Asked Questions
How many CVEs affect Apple?
Apple has 28,601 CVE records in our database, including 1791 critical and 14441 high severity vulnerabilities. 117 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Apple vulnerabilities?
Apple has 1791 critical severity (CVSS 9.0+) and 14441 high severity (CVSS 7.0-8.9) vulnerabilities. 117 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Apple vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Apple products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Apple Vulnerabilities
CyberStrike scans your infrastructure for Apple vulnerabilities and provides real-time remediation guidance.
Get Started