apple
1,466 known vulnerabilities affecting apple products.
Products
macos 1342
iphone_os 402
ipados 306
visionos 178
watchos 160
tvos 158
safari 66
mac_os_x 4
container 2
swift-crypto 2
swiftnio 1
swiftnio_http\/2 1
swiftnio_ssh 1
swiftnio_ssl 1
servicetalk 1
xcode 1
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-10965 | Medium | 0.4% | 8.8 | Integer overflow in DevTools in Google Chrome prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-10987 | Medium | 0.4% | 8.8 | Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote … | |
| CVE-2026-10991 | Medium | 0.4% | 8.8 | Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote at… | |
| CVE-2026-11046 | Medium | 0.4% | 8.8 | Insufficient validation of untrusted input in Media in Google Chrome prior to 14… | |
| CVE-2026-10893 | Medium | 0.4% | 8.8 | Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-10945 | Medium | 0.4% | 8.8 | Use after free in PDF in Google Chrome prior to 149.0.7827.53 allowed a remote a… | |
| CVE-2026-7333 | Medium | 0.4% | 9.6 | Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote … | |
| CVE-2026-7334 | Medium | 0.4% | 8.8 | Use after free in Views in Google Chrome on Mac prior to 147.0.7727.138 allowed … | |
| CVE-2026-11662 | Medium | 0.4% | 8.8 | Type Confusion in Bindings in Google Chrome prior to 149.0.7827.103 allowed a re… | |
| CVE-2026-19875 | Medium | 0.4% | 7.5 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite… | |
| CVE-2026-34691 | Medium | 0.4% | 9.3 | Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are af… | |
| CVE-2026-27220 | Medium | 0.4% | 7.8 | Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are… | |
| CVE-2026-11054 | Medium | 0.4% | 8.8 | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-11068 | Medium | 0.4% | 8.8 | Use after free in WebSockets in Google Chrome prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-9962 | Medium | 0.4% | 8.8 | Use after free in WebRTC in Google Chrome prior to 148.0.7778.216 allowed a remo… | |
| CVE-2026-11024 | Medium | 0.4% | 8.8 | Stack buffer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a … | |
| CVE-2026-5859 | Medium | 0.4% | 8.8 | Integer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remo… | |
| CVE-2026-13445 | Medium | 0.4% | 8.1 | IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exp… | |
| CVE-2026-28990 | Medium | 0.3% | 7.5 | The issue was addressed with improved memory handling. This issue is fixed in iO… | |
| CVE-2026-10886 | Medium | 0.3% | 9.6 | Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-10901 | Medium | 0.3% | 7.5 | Use after free in Passwords in Google Chrome on Mac prior to 149.0.7827.53 allow… | |
| CVE-2024-44219 | Medium | 0.3% | 7.5 | A permissions issue was addressed with additional restrictions. This issue is fi… | |
| CVE-2024-44286 | Medium | 0.3% | 7.5 | This issue was addressed through improved state management. This issue is fixed … | |
| CVE-2026-7754 | Medium | 0.3% | 7.7 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side req… | |
| CVE-2026-5868 | Medium | 0.3% | 8.8 | Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 all… | |
| CVE-2026-65381 | Medium | 0.3% | 10.0 | A validation issue existed in the entitlement verification. This issue was addre… | |
| CVE-2026-79091 | Medium | 0.3% | 9.6 | Use after free in Bluetooth in Google Chrome on on Mac prior to 152.0.7977.65 al… | |
| CVE-2026-11651 | Medium | 0.3% | 9.6 | Use after free in Network in Google Chrome prior to 149.0.7827.103 allowed a rem… | |
| CVE-2026-43798 | Medium | 0.3% | 9.8 | A single crafted SSH message gives an unauthenticated network attacker an out-of… | |
| CVE-2026-48339 | Medium | 0.3% | 7.8 | Bridge is affected by a Heap-based Buffer Overflow vulnerability that could resu… | |
| CVE-2026-48373 | Medium | 0.3% | 7.8 | Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that co… | |
| CVE-2026-64725 | Medium | 0.3% | 7.1 | An out-of-bounds write issue was addressed with improved bounds checking. This i… | |
| CVE-2026-7354 | Medium | 0.3% | 8.8 | Out of bounds read and write in Angle in Google Chrome prior to 147.0.7727.138 a… | |
| CVE-2026-7359 | Medium | 0.3% | 8.8 | Use after free in ANGLE in Google Chrome prior to 147.0.7727.138 allowed a remot… | |
| CVE-2026-84543 | Medium | 0.3% | 7.5 | An out-of-bounds access issue was addressed with improved bounds checking. This … | |
| CVE-2026-84563 | Medium | 0.3% | 7.5 | A logic issue was addressed with improved checks. This issue is fixed in macOS G… | |
| CVE-2026-10898 | Medium | 0.3% | 8.3 | Stack buffer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-17967 | Medium | 0.3% | 8.8 | Use after free in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 … | |
| CVE-2026-43735 | Medium | 0.3% | 8.1 | The issue was addressed with improved checks. This issue is fixed in Safari 26.5… | |
| CVE-2026-7339 | Medium | 0.3% | 8.8 | Heap buffer overflow in WebRTC in Google Chrome prior to 147.0.7727.138 allowed … | |
| CVE-2026-5871 | Medium | 0.3% | 8.8 | Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote at… | |
| CVE-2026-9121 | Medium | 0.3% | 8.8 | Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a … | |
| CVE-2026-47912 | Medium | 0.3% | 7.8 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a… | |
| CVE-2026-47913 | Medium | 0.3% | 7.8 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a… | |
| CVE-2026-47914 | Medium | 0.3% | 7.8 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a… | |
| CVE-2026-85047 | Medium | 0.3% | 9.6 | Improper input validation in Transactions Platform in Google Chrome on on iOS pr… | |
| CVE-2026-48350 | Medium | 0.3% | 8.6 | Animate is affected by an Improper Limitation of a Pathname to a Restricted Dire… | |
| CVE-2026-10906 | Medium | 0.3% | 7.5 | Use after free in WebAuthentication in Google Chrome prior to 149.0.7827.53 allo… | |
| CVE-2026-7361 | Medium | 0.3% | 8.8 | Use after free in iOS in Google Chrome prior to 147.0.7727.138 allowed a remote … | |
| CVE-2026-10897 | Medium | 0.3% | 8.8 | Inappropriate implementation in GPU in Google Chrome prior to 149.0.7827.53 allo… |