target entity

Apple

93 source-linked records in the current knowledge graph.

high

CVE-2025-43510: Apple Multiple Products Improper Locking Vulnerability

Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-43510EPSS 0.4%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2025-43520: Apple Multiple Products Classic Buffer Overflow Vulnerability

Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel memory. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-43520EPSS 0.4%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2025-31277: Apple Multiple Products Buffer Overflow Vulnerability

Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory corruption. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-31277EPSS 1.5%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2023-43000: Apple Multiple products Use-After-Free Vulnerability

Apple macOS, iOS, iPadOS, and Safari 16.6 contain a use-after-free vulnerability due to the processing of maliciously crafted web content that may lead to memory corruption. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2023-43000EPSS 4.0%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30952: Apple Multiple Products Integer Overflow or Wraparound Vulnerability

Apple tvOS, macOS, Safari, iPadOS and watchOS contain an integer overflow or wraparound vulnerability due to the processing of maliciously crafted web content that may lead to arbitrary code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2021-30952EPSS 7.6%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2023-41974: Apple iOS and iPadOS Use-After-Free Vulnerability

Apple iOS and iPadOS contain a use-after-free vulnerability. An app may be able to execute arbitrary code with kernel privileges. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2023-41974EPSS 1.4%AppleiOS and iPadOS
CISA KEV ↗ · unattributed attribution
high

CVE-2026-20700: Apple Multiple Buffer Overflow Vulnerability

Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow an attacker with memory write the capability to execute arbitrary code. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-20700EPSS 1.3%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2025-43529: Apple Multiple Products Use-After-Free WebKit Vulnerability

Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing maliciously crafted web content may lead to memory corruption. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-43529EPSS 8.6%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2022-48503: Apple Multiple Products Unspecified Vulnerability

Apple macOS, iOS, tvOS, Safari, and watchOS contain an unspecified vulnerability in JavaScriptCore that when processing web content may lead to arbitrary code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2022-48503EPSS 3.2%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2025-43300: Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability

Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-43300EPSS 20.0%AppleiOS, iPadOS, and macOS
CISA KEV ↗ · unattributed attribution
high

CVE-2025-43200: Apple Multiple Products Unspecified Vulnerability

Apple iOS, iPadOS, macOS, watchOS, and visionOS, contain an unspecified vulnerability when processing a maliciously crafted photo or video shared via an iCloud Link. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-43200EPSS 1.0%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2025-31201: Apple Multiple Products Arbitrary Read and Write Vulnerability

Apple iOS, iPadOS, macOS, and other Apple products contain an arbitrary read and write vulnerability that allows an attacker to bypass Pointer Authentication. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-31201EPSS 12.8%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2025-31200: Apple Multiple Products Memory Corruption Vulnerability

Apple iOS, iPadOS, macOS, and other Apple products contain a memory corruption vulnerability that allows for code execution when processing an audio stream in a maliciously crafted media file. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-31200EPSS 21.9%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24201: Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability

Apple iOS, iPadOS, macOS, and other Apple products contain an out-of-bounds write vulnerability in WebKit that may allow maliciously crafted web content to break out of Web Content sandbox. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24201EPSS 4.2%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24200: Apple iOS and iPadOS Incorrect Authorization Vulnerability

Apple iOS and iPadOS contains an incorrect authorization vulnerability that allows a physical attacker to disable USB Restricted Mode on a locked device. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2025-24200EPSS 4.4%AppleiOS and iPadOS
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24085: Apple Multiple Products Use-After-Free Vulnerability

Apple iOS, macOS, and other Apple products contain a user-after-free vulnerability that could allow a malicious application to elevate privileges. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2025-24085EPSS 18.7%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2024-44309: Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability

Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to a cross-site scripting (XSS) attack. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-44309EPSS 22.7%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2024-44308: Apple Multiple Products Code Execution Vulnerability

Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to arbitrary code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-44308EPSS 9.2%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2024-23225: Apple Multiple Products Memory Corruption Vulnerability

Apple iOS, iPadOS, macOS, tvOS, watchOS, and visionOS kernel contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-23225EPSS 1.5%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2024-23296: Apple Multiple Products Memory Corruption Vulnerability

Apple iOS, iPadOS, macOS, tvOS, and watchOS RTKit contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-23296EPSS 1.4%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2022-48618: Apple Multiple Products Memory Corruption Vulnerability

Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a time-of-check/time-of-use (TOCTOU) memory corruption vulnerability that allows an attacker with read and write capabilities to bypass Pointer Authentication. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2022-48618EPSS 0.5%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2024-23222: Apple Multiple Products WebKit Type Confusion Vulnerability

Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-23222EPSS 10.6%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2023-41990: Apple Multiple Products Code Execution Vulnerability

Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability that allows for code execution when processing a font file. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-41990EPSS 1.1%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2023-42917: Apple Multiple Products WebKit Memory Corruption Vulnerability

Apple iOS, iPadOS, macOS, and Safari WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

CVE-2023-42917EPSS 9.4%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2023-42916: Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability

Apple iOS, iPadOS, macOS, and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

CVE-2023-42916EPSS 17.8%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2023-41993: Apple Multiple Products WebKit Code Execution Vulnerability

Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-41993EPSS 29.2%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2023-41064: Apple iOS, iPadOS, and macOS ImageIO Buffer Overflow Vulnerability

Apple iOS, iPadOS, and macOS contain a buffer overflow vulnerability in ImageIO when processing a maliciously crafted image, which may lead to code execution. This vulnerability was chained with CVE-2023-41061. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-41061CVE-2023-41064EPSS 15.3%AppleiOS, iPadOS, and macOS
CISA KEV ↗ · unattributed attribution
high

CVE-2023-41061: Apple iOS, iPadOS, and watchOS Wallet Code Execution Vulnerability

Apple iOS, iPadOS, and watchOS contain an unspecified vulnerability due to a validation issue affecting Wallet in which a maliciously crafted attachment may result in code execution. This vulnerability was chained with CVE-2023-41064. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-41061CVE-2023-41064EPSS 15.3%AppleiOS, iPadOS, and watchOS
CISA KEV ↗ · unattributed attribution
high

CVE-2023-38606: Apple Multiple Products Kernel Unspecified Vulnerability

Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability allowing an app to modify a sensitive kernel state. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-38606EPSS 1.0%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2023-37450: Apple Multiple Products WebKit Code Execution Vulnerability

Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

CVE-2023-37450EPSS 18.9%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2023-32435: Apple Multiple Products WebKit Memory Corruption Vulnerability

Apple iOS, iPadOS, macOS, and Safari WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2023-32435EPSS 23.0%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2023-32439: Apple Multiple Products WebKit Type Confusion Vulnerability

Apple iOS, iPadOS, macOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2023-32439EPSS 23.8%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2023-32409: Apple Multiple Products WebKit Sandbox Escape Vulnerability

Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an unspecified vulnerability that can allow a remote attacker to break out of the Web Content sandbox. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2023-32409EPSS 16.5%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2023-28204: Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability

Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2023-28204EPSS 14.3%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2023-32373: Apple Multiple Products WebKit Use-After-Free Vulnerability

Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2023-32373EPSS 12.2%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2023-28205: Apple Multiple Products WebKit Use-After-Free Vulnerability

Apple iOS, iPadOS, macOS, and Safari WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2023-28205EPSS 27.1%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2023-23529: Apple Multiple Products WebKit Type Confusion Vulnerability

Apple iOS, MacOS, Safari and iPadOS WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2023-23529EPSS 9.5%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2016-4656: Apple iOS Memory Corruption Vulnerability

A memory corruption vulnerability in Apple iOS kernel allows attackers to execute code in a privileged context or cause a denial-of-service (DoS) via a crafted application. Required action: Apply updates per vendor instructions.

CVE-2016-4656EPSS 23.6%AppleiOS
CISA KEV ↗ · unattributed attribution
high

CVE-2016-4657: Apple iOS Webkit Memory Corruption Vulnerability

Apple iOS WebKit contains a memory corruption vulnerability that allows attackers to execute remote code or cause a denial-of-service (DoS) via a crafted web site. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2016-4657EPSS 66.8%AppleiOS
CISA KEV ↗ · unattributed attribution
high

CVE-2022-22620: Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability

Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2022-22620EPSS 16.3%AppleiOS, iPadOS, and macOS
CISA KEV ↗ · unattributed attribution
high

CVE-2014-4404: Apple OS X Heap-Based Buffer Overflow Vulnerability

Heap-based buffer overflow in IOHIDFamily in Apple OS X, which affects, iOS before 8 and Apple TV before 7, allows attackers to execute arbitrary code in a privileged context. Required action: Apply updates per vendor instructions.

CVE-2014-4404EPSS 49.0%AppleOS X
CISA KEV ↗ · unattributed attribution
high

CVE-2022-22587: Apple Memory Corruption Vulnerability

Apple IOMobileFrameBuffer contains a memory corruption vulnerability which can allow a malicious application to execute arbitrary code with kernel privileges. Required action: Apply updates per vendor instructions.

CVE-2022-22587EPSS 11.6%AppleiOS and macOS
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30858: Apple iOS, iPadOS, macOS Use-After-Free Vulnerability

Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2021-30858EPSS 13.5%AppleiOS, iPadOS, and macOS
CISA KEV ↗ · unattributed attribution
high

CVE-2019-6223: Apple iOS and macOS Group Facetime Vulnerability

Apple iOS and macOS Group FaceTime contains an unspecified vulnerability where the call initiator can cause the recipient's Apple device to answer unknowingly or without user interaction. Required action: Apply updates per vendor instructions.

CVE-2019-6223EPSS 2.6%AppleiOS and macOS
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30860: Apple Multiple Products Integer Overflow Vulnerability

Apple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code execution when processing a maliciously crafted PDF. The vulnerability is also known under the moniker of FORCEDENTRY. Required action: Apply updates per vendor instructions.

CVE-2021-30860EPSS 76.0%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30762: Apple iOS WebKit Use-After-Free Vulnerability

Apple iOS WebKit contains a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2021-30762EPSS 11.0%AppleiOS
CISA KEV ↗ · unattributed attribution
high

CVE-2021-1870: Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability

Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2021-1870EPSS 7.9%AppleiOS, iPadOS, and macOS
CISA KEV ↗ · unattributed attribution
high

CVE-2021-1871: Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability

Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2021-1871EPSS 7.1%AppleiOS, iPadOS, and macOS
CISA KEV ↗ · unattributed attribution
high

CVE-2021-1879: Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability

Apple iOS, iPadOS, and watchOS WebKit contain an unspecified vulnerability that allows for universal cross-site scripting (XSS) when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2021-1879EPSS 7.1%AppleiOS, iPadOS, and watchOS
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30661: Apple Multiple Products WebKit Storage Use-After-Free Vulnerability

Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit Storage contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2021-30661EPSS 4.5%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30666: Apple iOS WebKit Buffer Overflow Vulnerability

Apple iOS WebKit contains a buffer-overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2021-30666EPSS 3.0%AppleiOS
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30713: Apple macOS Unspecified Vulnerability

Apple macOS Transparency, Consent, and Control (TCC) contains an unspecified permissions issue which may allow a malicious application to bypass privacy preferences. Required action: Apply updates per vendor instructions.

CVE-2021-30713EPSS 6.6%ApplemacOS
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30657: Apple macOS Unspecified Vulnerability

Apple macOS contains an unspecified logic issue in System Preferences that may allow a malicious application to bypass Gatekeeper checks. Required action: Apply updates per vendor instructions.

CVE-2021-30657EPSS 68.5%ApplemacOS
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30665: Apple Multiple Products WebKit Memory Corruption Vulnerability

Apple iOS, iPadOS, macOS, watchOS, and tvOS WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2021-30665EPSS 3.7%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30663: Apple Multiple Products WebKit Integer Overflow Vulnerability

Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain an integer overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2021-30663EPSS 3.7%AppleMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30761: Apple iOS WebKit Memory Corruption Vulnerability

Apple iOS WebKit contains a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. Required action: Apply updates per vendor instructions.

CVE-2021-30761EPSS 10.6%AppleiOS
CISA KEV ↗ · unattributed attribution