Product of Apple

iOS, iPadOS, and macOS

As of , 11 Apple iOS, iPadOS, and macOS vulnerabilities are on CISA's list of exploited vulnerabilities; 0 were added in 2026. Patch first: CVE-2020-9934.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2020-9934Input ValidationApple iOS, iPadOS, and macOSPatch this weekMetasploit module0.03
2CVE-2023-41064ImageIO Buffer OverflowApple iOS, iPadOS, and macOSPatch this weekEPSS 0.530.53
3CVE-2025-43300Out-of-Bounds WriteApple iOS, iPadOS, and macOSPatch soon0.32
4CVE-2023-28206IOSurfaceAccelerator Out-of-Bounds WriteApple iOS, iPadOS, and macOSPatch soon0.23
5CVE-2022-22620Webkit Use-After-FreeApple iOS, iPadOS, and macOSPatch soon0.16
6CVE-2021-30858iOS, iPadOS, macOS Use-After-FreeApple iOS, iPadOS, and macOSPatch soon0.13
7CVE-2021-1870WebKit Remote Code ExecutionApple iOS, iPadOS, and macOSPatch soon0.08
8CVE-2021-1871WebKit Remote Code ExecutionApple iOS, iPadOS, and macOSPatch soon0.07
9CVE-2021-30900Out-of-Bounds WriteApple iOS, iPadOS, and macOSPatch soon0.05
10CVE-2022-32917Remote Code ExecutionApple iOS, iPadOS, and macOSPatch soon0.06
11CVE-2021-30869Type ConfusionApple iOS, iPadOS, and macOSPatch soon0.04

Added each year

12342021: 4420212022: 3320222023: 3320232024: nonenone20242025: 1120252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20214
20223
20233
2024none
20251
2026none

Used in ransomware