apple
1,466 known vulnerabilities affecting apple products.
Products
macos 1342
iphone_os 402
ipados 306
visionos 178
watchos 160
tvos 158
safari 66
mac_os_x 4
container 2
swift-crypto 2
swiftnio 1
swiftnio_http\/2 1
swiftnio_ssh 1
swiftnio_ssl 1
servicetalk 1
xcode 1
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-21287 | Medium | 0.2% | 7.8 | Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free… | |
| CVE-2026-5902 | Medium | 0.2% | 9.8 | Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remot… | |
| CVE-2026-11169 | Medium | 0.2% | 8.1 | Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allo… | |
| CVE-2026-6406 | Medium | 0.2% | 8.8 | The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI)… | |
| CVE-2026-76199 | Medium | 0.2% | 8.6 | Photoshop Desktop is affected by an Uncontrolled Search Path Element vulnerabili… | |
| CVE-2026-11301 | Medium | 0.2% | 8.8 | Inappropriate implementation in LiveCaption in Google Chrome prior to 149.0.7827… | |
| CVE-2026-34687 | Medium | 0.2% | 7.8 | Illustrator versions 29.8.6, 30.3 and earlier are affected by a Heap-based Buffe… | |
| CVE-2026-47916 | Medium | 0.2% | 7.8 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a… | |
| CVE-2026-81992 | Medium | 0.2% | 7.8 | Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that co… | |
| CVE-2026-11154 | Medium | 0.2% | 7.5 | Use after free in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote … | |
| CVE-2026-43698 | Medium | 0.2% | 7.8 | An injection issue was addressed with improved validation. This issue is fixed i… | |
| CVE-2026-65370 | Medium | 0.2% | 7.5 | ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding which could… | |
| CVE-2026-86894 | Medium | 0.2% | 7.5 | A logic issue was addressed with improved checks. This issue is fixed in macOS G… | |
| CVE-2026-9946 | Medium | 0.2% | 8.3 | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remot… | |
| CVE-2026-9974 | Medium | 0.2% | 8.3 | Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a re… | |
| CVE-2026-11201 | Medium | 0.2% | 8.8 | Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.53 allowed … | |
| CVE-2026-64763 | Medium | 0.2% | 7.8 | An out-of-bounds write issue was addressed by removing the vulnerable code. This… | |
| CVE-2026-27287 | Medium | 0.2% | 7.8 | InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read v… | |
| CVE-2026-5913 | Medium | 0.2% | 8.1 | Out of bounds read in Blink in Google Chrome prior to 147.0.7727.55 allowed a re… | |
| CVE-2025-46281 | Medium | 0.2% | 8.8 | A logic issue was addressed with improved checks. This issue is fixed in macOS S… | |
| CVE-2026-11265 | Medium | 0.2% | 7.5 | Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.53… | |
| CVE-2026-11687 | Medium | 0.2% | 8.8 | Use after free in Dawn in Google Chrome on Mac prior to 149.0.7827.103 allowed a… | |
| CVE-2026-11697 | Medium | 0.2% | 9.6 | Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0… | |
| CVE-2026-11698 | Medium | 0.2% | 8.8 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allo… | |
| CVE-2026-11699 | Medium | 0.2% | 8.8 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allo… | |
| CVE-2026-43723 | Medium | 0.2% | 7.8 | A path handling issue was addressed with improved validation. This issue is fixe… | |
| CVE-2026-9881 | Medium | 0.2% | 9.0 | Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allo… | |
| CVE-2026-11293 | Medium | 0.2% | 9.6 | Use after free in Input in Google Chrome prior to 149.0.7827.53 allowed a remote… | |
| CVE-2026-18015 | Medium | 0.2% | 9.6 | Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922… | |
| CVE-2026-11185 | Medium | 0.2% | 8.1 | Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed an attacker… | |
| CVE-2025-46291 | Medium | 0.2% | 7.8 | A logic issue was addressed with improved validation. This issue is fixed in mac… | |
| CVE-2026-71399 | Medium | 0.2% | 7.8 | Adobe XD is affected by a Buffer Overflow vulnerability that could result in arb… | |
| CVE-2026-84581 | Medium | 0.2% | 8.4 | A buffer overflow was addressed with improved bounds checking. This issue is fix… | |
| CVE-2026-81973 | Medium | 0.2% | 7.8 | Acrobat Reader is affected by a Use After Free vulnerability that could result i… | |
| CVE-2026-81976 | Medium | 0.2% | 7.8 | Acrobat Reader is affected by a Use After Free vulnerability that could result i… | |
| CVE-2026-81985 | Medium | 0.2% | 7.8 | Acrobat Reader is affected by a Use After Free vulnerability that could result i… | |
| CVE-2026-81986 | Medium | 0.2% | 7.8 | Acrobat Reader is affected by a Use After Free vulnerability that could result i… | |
| CVE-2026-81988 | Medium | 0.2% | 7.8 | Acrobat Reader is affected by a Use After Free vulnerability that could result i… | |
| CVE-2026-81989 | Medium | 0.2% | 7.8 | Acrobat Reader is affected by a Use After Free vulnerability that could result i… | |
| CVE-2026-39877 | Medium | 0.2% | 7.8 | A memory corruption issue was addressed with improved memory handling. This issu… | |
| CVE-2026-43749 | Medium | 0.2% | 7.8 | A parsing issue in the handling of directory paths was addressed with improved p… | |
| CVE-2026-11213 | Medium | 0.2% | 9.6 | Insufficient validation of untrusted input in Reading Mode in Google Chrome prio… | |
| CVE-2026-5908 | Medium | 0.2% | 8.8 | Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remo… | |
| CVE-2026-5909 | Medium | 0.2% | 8.8 | Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remo… | |
| CVE-2026-5910 | Medium | 0.2% | 8.8 | Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remo… | |
| CVE-2026-34618 | Medium | 0.2% | 7.8 | Illustrator versions 30.2, 29.8.5 and earlier are affected by an out-of-bounds w… | |
| CVE-2026-5915 | Medium | 0.2% | 8.1 | Insufficient validation of untrusted input in WebML in Google Chrome prior to 14… | |
| CVE-2026-64764 | Medium | 0.2% | 7.8 | An out-of-bounds write issue was addressed with improved bounds checking. This i… | |
| CVE-2026-64765 | Medium | 0.2% | 7.8 | An integer overflow was addressed with improved input validation. This issue is … | |
| CVE-2026-28896 | Medium | 0.2% | 7.7 | The issue was addressed with improved memory handling. This issue is fixed in iO… |