Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVE-2025-43300EPSS 20.0%AppleiOS, iPadOS, and macOS
Apple iOS, iPadOS, and macOS contain a buffer overflow vulnerability in ImageIO when processing a maliciously crafted image, which may lead to code execution. This vulnerability was chained with CVE-2023-41061. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CVE-2023-41061CVE-2023-41064EPSS 15.3%AppleiOS, iPadOS, and macOS
Apple iOS, iPadOS, and macOS IOSurfaceAccelerator contain an out-of-bounds write vulnerability that allows an app to execute code with kernel privileges. Required action: Apply updates per vendor instructions.
CVE-2023-28206EPSS 24.5%AppleiOS, iPadOS, and macOS
Apple GPU drivers, included in iOS, iPadOS, and macOS, contain an out-of-bounds write vulnerability that may allow a malicious application to execute code with kernel privileges. Required action: Apply updates per vendor instructions.
CVE-2021-30900EPSS 5.2%AppleiOS, iPadOS, and macOS
Apple kernel, which is included in iOS, iPadOS, and macOS, contains an unspecified vulnerability where an application may be able to execute code with kernel privileges. Required action: Apply updates per vendor instructions.
CVE-2022-32917EPSS 5.6%AppleiOS, iPadOS, and macOS
Apple iOS, iPadOS, and macOS contain an unspecified vulnerability involving input validation which can allow a local attacker to view sensitive user information. Required action: Apply updates per vendor instructions.
Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.
CVE-2022-22620EPSS 16.3%AppleiOS, iPadOS, and macOS
Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.
CVE-2021-30858EPSS 13.5%AppleiOS, iPadOS, and macOS
Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.
Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.
Apple iOS, iPadOS, and macOS contain a type confusion vulnerability in the XNU which may allow a malicious application to execute code with kernel privileges. Required action: Apply updates per vendor instructions.
CVE-2021-30869EPSS 4.2%AppleiOS, iPadOS, and macOS