Apple Multiple Products known exploited vulnerabilities, ranked
CISA lists 54 Apple Multiple Products CVEs as exploited in the wild. 9 were added in the last 12 months and 0 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.
Patch these first
- CVE-2021-30860: EPSS 76.0%, added 2021-11-03
- CVE-2023-32434: EPSS 51.5%, added 2023-06-23
- CVE-2021-30807: EPSS 28.8%, added 2021-11-03
- CVE-2023-28205: EPSS 27.1%, added 2023-04-10
- CVE-2023-41993: EPSS 24.3%, added 2023-09-25
All 54 Apple Multiple Products CVEs in CISA KEV, by EPSS
| # | CVE | Flaw | EPSS | Ransomware | Added | Federal due |
|---|---|---|---|---|---|---|
| 1 | CVE-2021-30860 | Multiple Products Integer Overflow | 76.0% | – | 2021-11-03 | 2021-11-17 |
| 2 | CVE-2023-32434 | Multiple Products Integer Overflow | 51.5% | – | 2023-06-23 | 2023-07-14 |
| 3 | CVE-2021-30807 | Multiple Products Memory Corruption | 28.8% | – | 2021-11-03 | 2021-11-17 |
| 4 | CVE-2023-28205 | Multiple Products WebKit Use-After-Free | 27.1% | – | 2023-04-10 | 2023-05-01 |
| 5 | CVE-2023-41993 | Multiple Products WebKit Code Execution | 24.3% | – | 2023-09-25 | 2023-10-16 |
| 6 | CVE-2023-32439 | Multiple Products WebKit Type Confusion | 24.0% | – | 2023-06-23 | 2023-07-14 |
| 7 | CVE-2023-32435 | Multiple Products WebKit Memory Corruption | 23.0% | – | 2023-06-23 | 2023-07-14 |
| 8 | CVE-2024-44309 | Multiple Products Cross-Site Scripting (XSS) | 22.6% | – | 2024-11-21 | 2024-12-12 |
| 9 | CVE-2020-27930 | Multiple Products Memory Corruption | 22.0% | – | 2021-11-03 | 2022-05-03 |
| 10 | CVE-2023-37450 | Multiple Products WebKit Code Execution | 18.9% | – | 2023-07-13 | 2023-08-03 |
| 11 | CVE-2025-31200 | Multiple Products Memory Corruption | 18.8% | – | 2025-04-17 | 2025-05-08 |
| 12 | CVE-2023-42916 | Multiple Products WebKit Out-of-Bounds Read | 17.8% | – | 2023-12-04 | 2023-12-25 |
| 13 | CVE-2019-8605 | Multiple Products Use-After-Free | 17.6% | – | 2022-06-27 | 2022-07-18 |
| 14 | CVE-2025-24085 | Multiple Products Use-After-Free | 17.5% | – | 2025-01-29 | 2025-02-19 |
| 15 | CVE-2023-32409 | Multiple Products WebKit Sandbox Escape | 16.5% | – | 2023-05-22 | 2023-06-12 |
| 16 | CVE-2020-27950 | Multiple Products Memory Initialization | 16.5% | – | 2021-11-03 | 2022-05-03 |
| 17 | CVE-2019-8506 | Multiple Products Type Confusion | 16.2% | – | 2022-05-04 | 2022-05-25 |
| 18 | CVE-2019-7286 | Multiple Products Memory Corruption | 15.9% | – | 2022-05-23 | 2022-06-13 |
| 19 | CVE-2020-3837 | Multiple Products Memory Corruption | 14.7% | – | 2022-06-27 | 2022-07-18 |
| 20 | CVE-2021-30883 | Multiple Products Memory Corruption | 14.7% | – | 2022-05-23 | 2022-06-13 |
| 21 | CVE-2023-28204 | Multiple Products WebKit Out-of-Bounds Read | 14.3% | – | 2023-05-22 | 2023-06-12 |
| 22 | CVE-2021-1789 | Multiple Products Type Confusion | 14.0% | – | 2022-05-04 | 2022-05-25 |
| 23 | CVE-2025-31201 | Multiple Products Arbitrary Read and Write | 14.0% | – | 2025-04-17 | 2025-05-08 |
| 24 | CVE-2023-41991 | Multiple Products Improper Certificate Validation | 13.4% | – | 2023-09-25 | 2023-10-16 |
| 25 | CVE-2023-32373 | Multiple Products WebKit Use-After-Free | 12.2% | – | 2023-05-22 | 2023-06-12 |
| 26 | CVE-2024-23222 | Multiple Products WebKit Type Confusion | 10.6% | – | 2024-01-23 | 2024-02-13 |
| 27 | CVE-2020-27932 | Multiple Products Type Confusion | 10.3% | – | 2021-11-03 | 2022-05-03 |
| 28 | CVE-2024-44308 | Multiple Products Code Execution | 10.1% | – | 2024-11-21 | 2024-12-12 |
| 29 | CVE-2023-41992 | Multiple Products Kernel Privilege Escalation | 9.5% | – | 2023-09-25 | 2023-10-16 |
| 30 | CVE-2023-23529 | Multiple Products WebKit Type Confusion | 9.5% | – | 2023-02-14 | 2023-03-07 |
| 31 | CVE-2023-42917 | Multiple Products WebKit Memory Corruption | 9.3% | – | 2023-12-04 | 2023-12-25 |
| 32 | CVE-2025-43529 | Multiple Products Use-After-Free WebKit | 8.8% | – | 2025-12-15 | 2026-01-05 |
| 33 | CVE-2021-30952 | Multiple Products Integer Overflow or Wraparound | 7.0% | – | 2026-03-05 | 2026-03-26 |
| 34 | CVE-2021-30661 | Multiple Products WebKit Storage Use-After-Free | 4.5% | – | 2021-11-03 | 2021-11-17 |
| 35 | CVE-2023-43000 | Multiple products Use-After-Free | 3.9% | – | 2026-03-05 | 2026-03-26 |
| 36 | CVE-2025-24201 | Multiple Products WebKit Out-of-Bounds Write | 3.8% | – | 2025-03-13 | 2025-04-03 |
| 37 | CVE-2021-30665 | Multiple Products WebKit Memory Corruption | 3.7% | – | 2021-11-03 | 2021-11-17 |
| 38 | CVE-2021-30663 | Multiple Products WebKit Integer Overflow | 3.5% | – | 2021-11-03 | 2021-11-17 |
| 39 | CVE-2022-48503 | Multiple Products Unspecified | 3.2% | – | 2025-10-20 | 2025-11-10 |
| 40 | CVE-2020-9907 | Multiple Products Memory Corruption | 3.2% | – | 2022-06-27 | 2022-07-18 |
| 41 | CVE-2023-38606 | Multiple Products Kernel Unspecified | 2.9% | – | 2023-07-26 | 2023-08-16 |
| 42 | CVE-2018-4344 | Multiple Products Memory Corruption | 2.4% | – | 2022-06-27 | 2022-07-18 |
| 43 | CVE-2021-1782 | Multiple Products Race Condition | 2.2% | – | 2021-11-03 | 2021-11-17 |
| 44 | CVE-2025-31277 | Multiple Products Buffer Overflow | 1.6% | – | 2026-03-20 | 2026-04-03 |
| 45 | CVE-2024-23225 | Multiple Products Memory Corruption | 1.5% | – | 2024-03-06 | 2024-03-27 |
| 46 | CVE-2024-23296 | Multiple Products Memory Corruption | 1.4% | – | 2024-03-06 | 2024-03-27 |
| 47 | CVE-2023-41990 | Multiple Products Code Execution | 1.4% | – | 2024-01-08 | 2024-01-29 |
| 48 | CVE-2026-20700 | Multiple Buffer Overflow | 1.4% | – | 2026-02-12 | 2026-03-05 |
| 49 | CVE-2026-86950 | Multiple Products Out-of-Bounds Write | 1.2% | – | 2026-09-29 | 2026-10-02 |
| 50 | CVE-2025-43200 | Multiple Products Unspecified | 1.2% | – | 2025-06-16 | 2025-07-07 |
| 51 | CVE-2020-9859 | Multiple Products Code Execution | 0.8% | – | 2021-11-03 | 2022-05-03 |
| 52 | CVE-2022-48618 | Multiple Products Memory Corruption | 0.5% | – | 2024-01-31 | 2024-02-21 |
| 53 | CVE-2025-43520 | Multiple Products Classic Buffer Overflow | 0.4% | – | 2026-03-20 | 2026-04-03 |
| 54 | CVE-2025-43510 | Multiple Products Improper Locking | 0.4% | – | 2026-03-20 | 2026-04-03 |
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint.
Sources: CISA KEV, FIRST EPSS.
More: all Apple KEV CVEs · other Apple products: macOS · iOS and iPadOS · iOS, iPadOS, and macOS · iOS · free KEV badge for Apple · all vendors