apple
1,466 known vulnerabilities affecting apple products.
Products
macos 1342
iphone_os 402
ipados 306
visionos 178
watchos 160
tvos 158
safari 66
mac_os_x 4
container 2
swift-crypto 2
swiftnio 1
swiftnio_http\/2 1
swiftnio_ssh 1
swiftnio_ssl 1
servicetalk 1
xcode 1
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-10907 | Medium | 0.3% | 8.8 | Out of bounds write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-43724 | Medium | 0.3% | 7.8 | The issue was addressed with improved input sanitization. This issue is fixed in… | |
| CVE-2026-84520 | Medium | 0.3% | 9.8 | A buffer overflow was addressed with improved size validation. This issue is fix… | |
| CVE-2026-9910 | Medium | 0.3% | 8.8 | Out of bounds memory access in ANGLE in Google Chrome prior to 148.0.7778.216 al… | |
| CVE-2026-20622 | Medium | 0.3% | 7.5 | A privacy issue was addressed with improved handling of temporary files. This is… | |
| CVE-2026-39875 | Medium | 0.3% | 7.8 | A permissions issue was addressed with additional restrictions. This issue is fi… | |
| CVE-2026-10013 | Medium | 0.3% | 8.8 | Use after free in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a r… | |
| CVE-2026-7353 | Medium | 0.3% | 8.3 | Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.138 allowed a … | |
| CVE-2026-9938 | Medium | 0.3% | 8.8 | Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.216 allo… | |
| CVE-2026-43658 | Medium | 0.3% | 7.5 | The issue was addressed with improved memory handling. This issue is fixed in Sa… | |
| CVE-2026-64761 | Medium | 0.3% | 7.5 | A privacy issue was addressed with improved handling of user preferences. This i… | |
| CVE-2026-7346 | Medium | 0.3% | 8.1 | Inappropriate implementation in Tint in Google Chrome prior to 147.0.7727.138 al… | |
| CVE-2026-10930 | Medium | 0.3% | 8.1 | Out of bounds read in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allow… | |
| CVE-2026-11015 | Medium | 0.3% | 8.1 | Out of bounds read in WebGPU in Google Chrome prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-87637 | Medium | 0.3% | 9.6 | Use after free in Extensions in Google Chrome on on Mac prior to 153.0.8010.36 a… | |
| CVE-2026-64773 | Medium | 0.3% | 7.5 | An attacker that can reach a container's published TCP port may be able to force… | |
| CVE-2026-11649 | Medium | 0.3% | 8.8 | Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote a… | |
| CVE-2026-11650 | Medium | 0.3% | 8.8 | Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote a… | |
| CVE-2026-48342 | Medium | 0.3% | 7.8 | Bridge is affected by an Integer Overflow or Wraparound vulnerability that could… | |
| CVE-2026-10951 | Medium | 0.3% | 8.8 | Use after free in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowe… | |
| CVE-2026-10952 | Medium | 0.3% | 8.8 | Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 … | |
| CVE-2026-11076 | Medium | 0.3% | 8.8 | Type Confusion in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote a… | |
| CVE-2026-9878 | Medium | 0.3% | 8.8 | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remot… | |
| CVE-2026-9973 | Medium | 0.3% | 8.8 | Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a rem… | |
| CVE-2026-10949 | Medium | 0.3% | 8.3 | Heap buffer overflow in Video in Google Chrome prior to 149.0.7827.53 allowed a … | |
| CVE-2026-11011 | Medium | 0.3% | 8.1 | Insufficient policy enforcement in Password Manager in Google Chrome prior to 14… | |
| CVE-2026-86881 | Medium | 0.3% | 9.1 | A certificate validation issue was addressed with improved certificate validatio… | |
| CVE-2026-43789 | Medium | 0.3% | 7.5 | An access issue was addressed with additional sandbox restrictions. This issue i… | |
| CVE-2026-65342 | Medium | 0.3% | 7.5 | A permissions issue was addressed with improved validation. This issue is fixed … | |
| CVE-2026-65378 | Medium | 0.3% | 7.5 | An authorization issue was addressed with improved state management. This issue … | |
| CVE-2026-7344 | Medium | 0.3% | 8.8 | Use after free in Accessibility in Google Chrome on Windows prior to 147.0.7727.… | |
| CVE-2026-11683 | Medium | 0.3% | 8.8 | Use after free in WebCodecs in Google Chrome prior to 149.0.7827.103 allowed a r… | |
| CVE-2026-19304 | Medium | 0.3% | 7.7 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacke… | |
| CVE-2026-47915 | Medium | 0.3% | 7.8 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a… | |
| CVE-2026-47917 | Medium | 0.3% | 7.8 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a… | |
| CVE-2026-14525 | Medium | 0.3% | 9.4 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphe… | |
| CVE-2026-43697 | Medium | 0.3% | 7.1 | An out-of-bounds read was addressed with improved bounds checking. This issue is… | |
| CVE-2026-7345 | Medium | 0.3% | 8.3 | Insufficient validation of untrusted input in Feedback in Google Chrome prior to… | |
| CVE-2026-10911 | Medium | 0.3% | 8.3 | Insufficient validation of untrusted input in Media in Google Chrome prior to 14… | |
| CVE-2026-10917 | Medium | 0.3% | 8.3 | Insufficient validation of untrusted input in Media in Google Chrome prior to 14… | |
| CVE-2026-10920 | Medium | 0.3% | 8.3 | Insufficient validation of untrusted input in WebShare in Google Chrome on Mac p… | |
| CVE-2026-14973 | Medium | 0.3% | 9.3 | IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow fil… | |
| CVE-2026-27243 | Medium | 0.3% | 9.3 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cro… | |
| CVE-2026-27245 | Medium | 0.3% | 9.3 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cro… | |
| CVE-2026-27246 | Medium | 0.3% | 9.3 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cro… | |
| CVE-2026-81994 | Medium | 0.3% | 8.2 | Acrobat Reader is affected by an Improperly Controlled Modification of Object Pr… | |
| CVE-2026-10922 | Medium | 0.3% | 8.8 | Insufficient validation of untrusted input in DevTools in Google Chrome prior to… | |
| CVE-2026-5861 | Medium | 0.3% | 8.8 | Use after free in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote at… | |
| CVE-2026-5862 | Medium | 0.3% | 8.8 | Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allow… | |
| CVE-2026-5866 | Medium | 0.3% | 8.8 | Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote… |