Apple known exploited vulnerabilities
CISA lists 94 Apple CVEs as exploited in the wild. 10 were added in the last 12 months (latest 2026-08-18), and 0 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2021-30860 (Multiple Products): EPSS 76.0%, added 2021-11-03
- CVE-2021-30657 (macOS): EPSS 68.5%, added 2021-11-03
- CVE-2016-4657 (iOS): EPSS 66.8%, added 2022-05-24
- CVE-2023-41064 (iOS, iPadOS, and macOS): EPSS 53.4%, added 2023-09-11
- CVE-2023-32434 (Multiple Products): EPSS 51.5%, added 2023-06-23
Most affected Apple products
Multiple Products (53), iOS, iPadOS, and macOS (11), iOS (8), macOS (6), iOS and iPadOS (5), iOS, iPadOS, and watchOS (4), iOS and macOS (4), OS X (2), iOS, macOS, watchOS (1).
All Apple CVEs in KEV (latest 60)
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2026-65400 | macOS | macOS Improper Authentication | 2026-08-18 | 2026-08-21 | 1.2% | – |
| CVE-2025-43520 | Multiple Products | Multiple Products Classic Buffer Overflow | 2026-03-20 | 2026-04-03 | 0.4% | – |
| CVE-2025-43510 | Multiple Products | Multiple Products Improper Locking | 2026-03-20 | 2026-04-03 | 0.4% | – |
| CVE-2025-31277 | Multiple Products | Multiple Products Buffer Overflow | 2026-03-20 | 2026-04-03 | 1.6% | – |
| CVE-2023-43000 | Multiple Products | Multiple products Use-After-Free | 2026-03-05 | 2026-03-26 | 3.9% | – |
| CVE-2023-41974 | iOS and iPadOS | iOS and iPadOS Use-After-Free | 2026-03-05 | 2026-03-26 | 1.9% | – |
| CVE-2021-30952 | Multiple Products | Multiple Products Integer Overflow or Wraparound | 2026-03-05 | 2026-03-26 | 7.0% | – |
| CVE-2026-20700 | Multiple Products | Multiple Buffer Overflow | 2026-02-12 | 2026-03-05 | 1.3% | – |
| CVE-2025-43529 | Multiple Products | Multiple Products Use-After-Free WebKit | 2025-12-15 | 2026-01-05 | 8.8% | – |
| CVE-2022-48503 | Multiple Products | Multiple Products Unspecified | 2025-10-20 | 2025-11-10 | 3.2% | – |
| CVE-2025-43300 | iOS, iPadOS, and macOS | iOS, iPadOS, and macOS Out-of-Bounds Write | 2025-08-21 | 2025-09-11 | 22.0% | – |
| CVE-2025-43200 | Multiple Products | Multiple Products Unspecified | 2025-06-16 | 2025-07-07 | 1.2% | – |
| CVE-2025-31201 | Multiple Products | Multiple Products Arbitrary Read and Write | 2025-04-17 | 2025-05-08 | 14.0% | – |
| CVE-2025-31200 | Multiple Products | Multiple Products Memory Corruption | 2025-04-17 | 2025-05-08 | 18.8% | – |
| CVE-2025-24201 | Multiple Products | Multiple Products WebKit Out-of-Bounds Write | 2025-03-13 | 2025-04-03 | 3.8% | – |
| CVE-2025-24200 | iOS and iPadOS | iOS and iPadOS Incorrect Authorization | 2025-02-12 | 2025-03-05 | 4.5% | – |
| CVE-2025-24085 | Multiple Products | Multiple Products Use-After-Free | 2025-01-29 | 2025-02-19 | 17.5% | – |
| CVE-2024-44309 | Multiple Products | Multiple Products Cross-Site Scripting (XSS) | 2024-11-21 | 2024-12-12 | 22.6% | – |
| CVE-2024-44308 | Multiple Products | Multiple Products Code Execution | 2024-11-21 | 2024-12-12 | 10.1% | – |
| CVE-2024-23296 | Multiple Products | Multiple Products Memory Corruption | 2024-03-06 | 2024-03-27 | 1.4% | – |
| CVE-2024-23225 | Multiple Products | Multiple Products Memory Corruption | 2024-03-06 | 2024-03-27 | 1.5% | – |
| CVE-2022-48618 | Multiple Products | Multiple Products Memory Corruption | 2024-01-31 | 2024-02-21 | 0.5% | – |
| CVE-2024-23222 | Multiple Products | Multiple Products WebKit Type Confusion | 2024-01-23 | 2024-02-13 | 10.6% | – |
| CVE-2023-41990 | Multiple Products | Multiple Products Code Execution | 2024-01-08 | 2024-01-29 | 1.4% | – |
| CVE-2023-42917 | Multiple Products | Multiple Products WebKit Memory Corruption | 2023-12-04 | 2023-12-25 | 9.3% | – |
| CVE-2023-42916 | Multiple Products | Multiple Products WebKit Out-of-Bounds Read | 2023-12-04 | 2023-12-25 | 17.8% | – |
| CVE-2023-42824 | iOS and iPadOS | iOS and iPadOS Kernel Privilege Escalation | 2023-10-05 | 2023-10-26 | 0.9% | – |
| CVE-2023-41993 | Multiple Products | Multiple Products WebKit Code Execution | 2023-09-25 | 2023-10-16 | 24.3% | – |
| CVE-2023-41992 | Multiple Products | Multiple Products Kernel Privilege Escalation | 2023-09-25 | 2023-10-16 | 9.5% | – |
| CVE-2023-41991 | Multiple Products | Multiple Products Improper Certificate Validation | 2023-09-25 | 2023-10-16 | 13.4% | – |
| CVE-2023-41064 | iOS, iPadOS, and macOS | iOS, iPadOS, and macOS ImageIO Buffer Overflow | 2023-09-11 | 2023-10-02 | 53.4% | – |
| CVE-2023-41061 | iOS, iPadOS, and watchOS | iOS, iPadOS, and watchOS Wallet Code Execution | 2023-09-11 | 2023-10-02 | 3.8% | – |
| CVE-2023-38606 | Multiple Products | Multiple Products Kernel Unspecified | 2023-07-26 | 2023-08-16 | 2.9% | – |
| CVE-2023-37450 | Multiple Products | Multiple Products WebKit Code Execution | 2023-07-13 | 2023-08-03 | 18.9% | – |
| CVE-2023-32439 | Multiple Products | Multiple Products WebKit Type Confusion | 2023-06-23 | 2023-07-14 | 24.0% | – |
| CVE-2023-32435 | Multiple Products | Multiple Products WebKit Memory Corruption | 2023-06-23 | 2023-07-14 | 23.0% | – |
| CVE-2023-32434 | Multiple Products | Multiple Products Integer Overflow | 2023-06-23 | 2023-07-14 | 51.5% | – |
| CVE-2023-32409 | Multiple Products | Multiple Products WebKit Sandbox Escape | 2023-05-22 | 2023-06-12 | 16.5% | – |
| CVE-2023-32373 | Multiple Products | Multiple Products WebKit Use-After-Free | 2023-05-22 | 2023-06-12 | 12.2% | – |
| CVE-2023-28204 | Multiple Products | Multiple Products WebKit Out-of-Bounds Read | 2023-05-22 | 2023-06-12 | 14.3% | – |
| CVE-2019-8526 | macOS | macOS Use-After-Free | 2023-04-17 | 2023-05-08 | 0.7% | – |
| CVE-2023-28206 | iOS, iPadOS, and macOS | iOS, iPadOS, and macOS IOSurfaceAccelerator Out-of-Bounds Write | 2023-04-10 | 2023-05-01 | 23.2% | – |
| CVE-2023-28205 | Multiple Products | Multiple Products WebKit Use-After-Free | 2023-04-10 | 2023-05-01 | 27.1% | – |
| CVE-2021-30900 | iOS, iPadOS, and macOS | iOS, iPadOS, and macOS Out-of-Bounds Write | 2023-03-30 | 2023-04-20 | 5.2% | – |
| CVE-2023-23529 | Multiple Products | Multiple Products WebKit Type Confusion | 2023-02-14 | 2023-03-07 | 9.5% | – |
| CVE-2022-42856 | iOS | iOS Type Confusion | 2022-12-14 | 2023-01-04 | 8.5% | – |
| CVE-2022-42827 | iOS and iPadOS | iOS and iPadOS Out-of-Bounds Write | 2022-10-25 | 2022-11-15 | 1.0% | – |
| CVE-2022-32917 | iOS, iPadOS, and macOS | iOS, iPadOS, and macOS Remote Code Execution | 2022-09-14 | 2022-10-05 | 5.6% | – |
| CVE-2020-9934 | iOS, iPadOS, and macOS | iOS, iPadOS, and macOS Input Validation | 2022-09-08 | 2022-09-29 | 3.2% | – |
| CVE-2021-31010 | iOS, macOS, watchOS | iOS, macOS, watchOS Sandbox Bypass | 2022-08-25 | 2022-09-15 | 3.7% | – |
| CVE-2022-32894 | iOS and macOS | iOS and macOS Out-of-Bounds Write | 2022-08-18 | 2022-09-08 | 3.3% | – |
| CVE-2022-32893 | iOS and macOS | iOS and macOS Out-of-Bounds Write | 2022-08-18 | 2022-09-08 | 9.9% | – |
| CVE-2021-30983 | iOS and iPadOS | iOS and iPadOS Buffer Overflow | 2022-06-27 | 2022-07-18 | 2.9% | – |
| CVE-2020-9907 | Multiple Products | Multiple Products Memory Corruption | 2022-06-27 | 2022-07-18 | 3.2% | – |
| CVE-2020-3837 | Multiple Products | Multiple Products Memory Corruption | 2022-06-27 | 2022-07-18 | 14.7% | – |
| CVE-2019-8605 | Multiple Products | Multiple Products Use-After-Free | 2022-06-27 | 2022-07-18 | 17.6% | – |
| CVE-2018-4344 | Multiple Products | Multiple Products Memory Corruption | 2022-06-27 | 2022-07-18 | 2.4% | – |
| CVE-2016-4657 | iOS | iOS Webkit Memory Corruption | 2022-05-24 | 2022-06-14 | 66.8% | – |
| CVE-2016-4656 | iOS | iOS Memory Corruption | 2022-05-24 | 2022-06-14 | 23.6% | – |
| CVE-2016-4655 | iOS | iOS Information Disclosure | 2022-05-24 | 2022-06-14 | 33.4% | – |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors