apple
1,466 known vulnerabilities affecting apple products.
Products
macos 1342
iphone_os 402
ipados 306
visionos 178
watchos 160
tvos 158
safari 66
mac_os_x 4
container 2
swift-crypto 2
swiftnio 1
swiftnio_http\/2 1
swiftnio_ssh 1
swiftnio_ssl 1
servicetalk 1
xcode 1
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-11658 | Low | 0.2% | 6.5 | Insufficient validation of untrusted input in Extensions in Google Chrome prior … | |
| CVE-2026-28984 | Low | 0.2% | 4.3 | The issue was addressed with improved memory handling. This issue is fixed in Sa… | |
| CVE-2026-9115 | Low | 0.2% | 4.3 | Insufficient policy enforcement in Service Worker in Google Chrome on prior to 1… | |
| CVE-2026-21278 | Low | 0.2% | 5.5 | InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Out-of-bou… | |
| CVE-2026-11020 | Low | 0.2% | 6.5 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.… | |
| CVE-2026-43696 | Low | 0.2% | 5.3 | An authorization issue was addressed with improved entitlement checks. This issu… | |
| CVE-2026-9882 | Low | 0.2% | 6.5 | Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a rem… | |
| CVE-2026-11159 | Low | 0.2% | 4.3 | Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remo… | |
| CVE-2026-17822 | Low | 0.2% | 6.5 | Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a … | |
| CVE-2026-17841 | Low | 0.2% | 6.5 | Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a … | |
| CVE-2026-5886 | Low | 0.2% | 5.3 | Out of bounds read in WebAudio in Google Chrome on Mac prior to 147.0.7727.55 al… | |
| CVE-2026-9113 | Low | 0.2% | 4.3 | Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowe… | |
| CVE-2026-17917 | Low | 0.2% | 6.5 | Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior … | |
| CVE-2026-5881 | Low | 0.2% | 6.5 | Policy bypass in LocalNetworkAccess in Google Chrome prior to 147.0.7727.55 allo… | |
| CVE-2026-11193 | Low | 0.2% | 6.5 | Insufficient policy enforcement in Password Manager in Google Chrome prior to 14… | |
| CVE-2026-43674 | Low | 0.2% | 4.6 | An authentication issue was addressed with improved state management. This issue… | |
| CVE-2026-84600 | Low | 0.2% | 5.4 | An authorization issue was addressed with improved state management. This issue … | |
| CVE-2026-11014 | Low | 0.2% | 6.5 | Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.78… | |
| CVE-2026-11666 | Low | 0.2% | 5.4 | Insufficient validation of untrusted input in Input in Google Chrome prior to 14… | |
| CVE-2026-8447 | Low | 0.2% | 6.1 | IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site scripting … | |
| CVE-2026-11277 | Low | 0.2% | 4.3 | Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior … | |
| CVE-2025-43417 | Low | 0.2% | 5.5 | A path handling issue was addressed with improved logic. This issue is fixed in … | |
| CVE-2026-17874 | Low | 0.2% | 5.4 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to … | |
| CVE-2026-20679 | Low | 0.2% | 4.3 | The issue was addressed with improved checks. This issue is fixed in macOS Sequo… | |
| CVE-2026-64718 | Low | 0.2% | 5.5 | A use-after-free issue was addressed with improved memory management. This issue… | |
| CVE-2026-11069 | Low | 0.2% | 6.5 | Insufficient validation of untrusted input in Cast in Google Chrome prior to 149… | |
| CVE-2026-87452 | Low | 0.2% | 3.1 | Incorrect authorization in GPU in Google Chrome on on Mac prior to 153.0.8010.36… | |
| CVE-2025-43236 | Low | 0.2% | 3.3 | A type confusion issue was addressed with improved memory handling. This issue i… | |
| CVE-2026-11174 | Low | 0.2% | 5.3 | Inappropriate implementation in Site Isolation in Google Chrome prior to 149.0.7… | |
| CVE-2026-11244 | Low | 0.2% | 3.1 | Insufficient validation of untrusted input in WebAuthentication in Google Chrome… | |
| CVE-2026-21288 | Low | 0.2% | 5.5 | Illustrator versions 29.8.3, 30.0 and earlier are affected by a NULL Pointer Der… | |
| CVE-2026-64722 | Low | 0.2% | 5.5 | A buffer overflow issue was addressed with improved memory handling. This issue … | |
| CVE-2026-5891 | Low | 0.2% | 4.3 | Insufficient policy enforcement in browser UI in Google Chrome prior to 147.0.77… | |
| CVE-2026-11166 | Low | 0.2% | 6.8 | Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allo… | |
| CVE-2026-64699 | Low | 0.2% | 5.5 | A memory initialization issue was addressed with improved memory handling. This … | |
| CVE-2026-43765 | Low | 0.2% | 5.5 | This issue was addressed with improved handling of symlinks. This issue is fixed… | |
| CVE-2026-7360 | Low | 0.2% | 3.1 | Insufficient validation of untrusted input. in Compositing in Google Chrome prio… | |
| CVE-2026-87546 | Low | 0.2% | 4.3 | Incorrect type conversion or cast in Safebrowsing in Google Chrome on on Mac pri… | |
| CVE-2026-11031 | Low | 0.2% | 4.3 | Insufficient validation of untrusted input in Password Manager in Google Chrome … | |
| CVE-2025-43473 | Low | 0.2% | 5.5 | This issue was addressed with improved state management. This issue is fixed in … | |
| CVE-2026-11132 | Low | 0.2% | 6.5 | Insufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53… | |
| CVE-2026-11133 | Low | 0.2% | 6.5 | Insufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53… | |
| CVE-2026-11162 | Low | 0.2% | 4.3 | Inappropriate implementation in CSS in Google Chrome prior to 149.0.7827.53 allo… | |
| CVE-2026-11246 | Low | 0.2% | 5.3 | Insufficient validation of untrusted input in IndexedDB in Google Chrome prior t… | |
| CVE-2026-11078 | Low | 0.2% | 6.5 | Inappropriate implementation in FileSystem in Google Chrome prior to 149.0.7827.… | |
| CVE-2026-11135 | Low | 0.2% | 6.5 | Insufficient policy enforcement in Autofill in Google Chrome prior to 149.0.7827… | |
| CVE-2026-11142 | Low | 0.2% | 6.5 | Insufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53… | |
| CVE-2026-11197 | Low | 0.2% | 6.5 | Insufficient policy enforcement in Workers in Google Chrome prior to 149.0.7827.… | |
| CVE-2026-11204 | Low | 0.2% | 6.5 | Inappropriate implementation in Signin in Google Chrome on iOS prior to 149.0.78… | |
| CVE-2026-11258 | Low | 0.2% | 6.5 | Inappropriate implementation in File System Access in Google Chrome prior to 149… |