CyberMax
Home › Exploited CVEs › Apple

Apple iOS, iPadOS, and macOS known exploited vulnerabilities, ranked

CISA KEV catalog 2026.10.02 · FIRST EPSS scores from 2026-10-02

CISA lists 11 Apple iOS, iPadOS, and macOS CVEs as exploited in the wild. 0 were added in the last 12 months and 0 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.

Patch these first

All 11 Apple iOS, iPadOS, and macOS CVEs in CISA KEV, by EPSS

#CVEFlawEPSSRansomwareAddedFederal due
1CVE-2023-41064iOS, iPadOS, and macOS ImageIO Buffer Overflow53.4%–2023-09-112023-10-02
2CVE-2025-43300iOS, iPadOS, and macOS Out-of-Bounds Write32.5%–2025-08-212025-09-11
3CVE-2023-28206iOS, iPadOS, and macOS IOSurfaceAccelerator Out-of-Bounds Write23.2%–2023-04-102023-05-01
4CVE-2022-22620iOS, iPadOS, and macOS Webkit Use-After-Free16.3%–2022-02-112022-02-25
5CVE-2021-30858iOS, iPadOS, macOS Use-After-Free13.4%–2021-11-032021-11-17
6CVE-2021-1870iOS, iPadOS, and macOS WebKit Remote Code Execution7.7%–2021-11-032021-11-17
7CVE-2021-1871iOS, iPadOS, and macOS WebKit Remote Code Execution7.0%–2021-11-032021-11-17
8CVE-2022-32917iOS, iPadOS, and macOS Remote Code Execution5.6%–2022-09-142022-10-05
9CVE-2021-30900iOS, iPadOS, and macOS Out-of-Bounds Write5.2%–2023-03-302023-04-20
10CVE-2021-30869iOS, iPadOS, and macOS Type Confusion4.1%–2021-11-032021-11-17
11CVE-2020-9934iOS, iPadOS, and macOS Input Validation3.2%–2022-09-082022-09-29
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

More: all Apple KEV CVEs · other Apple products: Multiple Products · macOS · iOS and iPadOS · iOS · free KEV badge for Apple · all vendors