CyberMax
Home › Exploited CVEs › Apple

Apple iOS known exploited vulnerabilities, ranked

CISA KEV catalog 2026.10.02 · FIRST EPSS scores from 2026-10-02

CISA lists 8 Apple iOS CVEs as exploited in the wild. 0 were added in the last 12 months and 0 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.

Patch these first

All 8 Apple iOS CVEs in CISA KEV, by EPSS

#CVEFlawEPSSRansomwareAddedFederal due
1CVE-2016-4657iOS Webkit Memory Corruption66.8%–2022-05-242022-06-14
2CVE-2016-4655iOS Information Disclosure33.4%–2022-05-242022-06-14
3CVE-2016-4656iOS Memory Corruption23.6%–2022-05-242022-06-14
4CVE-2021-30762iOS WebKit Use-After-Free11.0%–2021-11-032021-11-17
5CVE-2021-30761iOS WebKit Memory Corruption10.5%–2021-11-032021-11-17
6CVE-2022-42856iOS Type Confusion8.5%–2022-12-142023-01-04
7CVE-2019-7287iOS Memory Corruption4.6%–2022-05-232022-06-13
8CVE-2021-30666iOS WebKit Buffer Overflow3.0%–2021-11-032021-11-17
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

More: all Apple KEV CVEs · other Apple products: Multiple Products · macOS · iOS and iPadOS · iOS, iPadOS, and macOS · free KEV badge for Apple · all vendors