apple
1,466 known vulnerabilities affecting apple products.
Products
macos 1342
iphone_os 402
ipados 306
visionos 178
watchos 160
tvos 158
safari 66
mac_os_x 4
container 2
swift-crypto 2
swiftnio 1
swiftnio_http\/2 1
swiftnio_ssh 1
swiftnio_ssl 1
servicetalk 1
xcode 1
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-11655 | Medium | 0.2% | 8.3 | Integer overflow in Media in Google Chrome on Mac prior to 149.0.7827.103 allowe… | |
| CVE-2026-64747 | Medium | 0.2% | 7.8 | A buffer overflow was addressed with improved size validation. This issue is fix… | |
| CVE-2026-11248 | Medium | 0.2% | 8.8 | Inappropriate implementation in Google Lens in Google Chrome prior to 149.0.7827… | |
| CVE-2026-28981 | Medium | 0.2% | 7.8 | A buffer overflow was addressed with improved bounds checking. This issue is fix… | |
| CVE-2026-11250 | Medium | 0.2% | 9.6 | Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53… | |
| CVE-2026-34630 | Medium | 0.2% | 7.8 | Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer O… | |
| CVE-2026-11303 | Medium | 0.2% | 8.8 | Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-21274 | Medium | 0.2% | 7.8 | Dreamweaver Desktop versions 21.6 and earlier are affected by an Incorrect Autho… | |
| CVE-2026-48349 | Medium | 0.2% | 8.1 | Animate is affected by an Incorrect Authorization vulnerability that could resul… | |
| CVE-2026-9960 | Medium | 0.2% | 7.5 | Integer overflow in PDFium in Google Chrome prior to 148.0.7778.216 allowed a re… | |
| CVE-2026-10021 | Medium | 0.2% | 8.8 | Insufficient validation of untrusted input in USB in Google Chrome prior to 148.… | |
| CVE-2026-11114 | Medium | 0.2% | 9.6 | Use after free in Device Trust in Google Chrome on Mac prior to 149.0.7827.53 al… | |
| CVE-2026-11124 | Medium | 0.2% | 8.8 | Integer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-11146 | Medium | 0.2% | 9.6 | Insufficient validation of untrusted input in Chromoting in Google Chrome prior … | |
| CVE-2026-11152 | Medium | 0.2% | 9.6 | Object lifecycle issue in Dawn in Google Chrome prior to 149.0.7827.53 allowed a… | |
| CVE-2026-11165 | Medium | 0.2% | 9.6 | Use after free in WebMIDI in Google Chrome on iOS prior to 149.0.7827.53 allowed… | |
| CVE-2026-11177 | Medium | 0.2% | 8.8 | Use after free in Omnibox in Google Chrome prior to 149.0.7827.53 allowed a remo… | |
| CVE-2026-11202 | Medium | 0.2% | 8.8 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to … | |
| CVE-2026-11272 | Medium | 0.2% | 8.8 | Insufficient validation of untrusted input in Reading List in Google Chrome on i… | |
| CVE-2026-17716 | Medium | 0.2% | 8.4 | Use after free in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed… | |
| CVE-2026-21357 | Medium | 0.2% | 7.8 | InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based … | |
| CVE-2026-27313 | Medium | 0.2% | 7.8 | Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer O… | |
| CVE-2026-9874 | Medium | 0.2% | 9.6 | Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote… | |
| CVE-2026-9978 | Medium | 0.2% | 8.8 | Use after free in Glic in Google Chrome prior to 148.0.7778.216 allowed a remote… | |
| CVE-2026-9992 | Medium | 0.2% | 8.8 | Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a rem… | |
| CVE-2026-9964 | Medium | 0.2% | 8.1 | Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allo… | |
| CVE-2024-40849 | Medium | 0.2% | 7.5 | A race condition was addressed with additional validation. This issue is fixed i… | |
| CVE-2026-11633 | Medium | 0.2% | 8.8 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allo… | |
| CVE-2026-11640 | Medium | 0.2% | 8.3 | Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a re… | |
| CVE-2026-11642 | Medium | 0.2% | 8.3 | Use after free in Web Apps in Google Chrome prior to 149.0.7827.103 allowed a re… | |
| CVE-2026-10006 | Medium | 0.2% | 7.5 | Race in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a remote attac… | |
| CVE-2026-21272 | Medium | 0.2% | 8.6 | Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input … | |
| CVE-2026-7343 | Medium | 0.2% | 7.5 | Use after free in Views in Google Chrome on Windows prior to 147.0.7727.138 allo… | |
| CVE-2026-11111 | Medium | 0.2% | 8.1 | Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a re… | |
| CVE-2026-11305 | Medium | 0.2% | 8.8 | Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-11307 | Medium | 0.2% | 8.8 | Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-21320 | Medium | 0.2% | 7.8 | After Effects versions 25.6 and earlier are affected by a Use After Free vulnera… | |
| CVE-2026-21323 | Medium | 0.2% | 7.8 | After Effects versions 25.6 and earlier are affected by a Use After Free vulnera… | |
| CVE-2026-21326 | Medium | 0.2% | 7.8 | After Effects versions 25.6 and earlier are affected by a Use After Free vulnera… | |
| CVE-2026-21329 | Medium | 0.2% | 7.8 | After Effects versions 25.6 and earlier are affected by a Use After Free vulnera… | |
| CVE-2026-21351 | Medium | 0.2% | 7.8 | After Effects versions 25.6 and earlier are affected by a Use After Free vulnera… | |
| CVE-2026-50526 | Medium | 0.2% | 7.0 | Improper link resolution before file access ('link following') in .NET allows an… | |
| CVE-2026-9880 | Medium | 0.2% | 8.3 | Insufficient validation of untrusted input in WebGL in Google Chrome prior to 14… | |
| CVE-2026-9885 | Medium | 0.2% | 8.3 | Insufficient validation of untrusted input in UI in Google Chrome on Mac prior t… | |
| CVE-2026-11179 | Medium | 0.2% | 8.8 | Inappropriate implementation in ORB in Google Chrome prior to 149.0.7827.53 allo… | |
| CVE-2026-75771 | Medium | 0.2% | 7.8 | Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability… | |
| CVE-2026-75862 | Medium | 0.2% | 7.8 | Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability… | |
| CVE-2026-75863 | Medium | 0.2% | 7.8 | Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability… | |
| CVE-2026-82007 | Medium | 0.2% | 7.8 | Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability… | |
| CVE-2026-9972 | Medium | 0.2% | 8.3 | Uninitialized Use in Gamepad in Google Chrome on Mac prior to 148.0.7778.216 all… |