How we count
Every figure on this page is a direct count of entries in CISA’s Known Exploited Vulnerabilities catalog attributed by CISA to Apple (KEV field vendorProject), refreshed daily. “Ransomware-linked” counts entries CISA marks as known to be used in ransomware campaigns; the remainder are “unknown” to CISA, not confirmed ransomware-free. A KEV listing means the vulnerability has been observed exploited in the wild. Snapshot as of 2026-08-31.
Exploited Apple vulnerabilities (CISA KEV)
| CVE | Product | Vulnerability | Added | |
|---|---|---|---|---|
| CVE-2026-65400 | macOS | Apple macOS Improper Authentication Vulnerability | 2026-08-18 | |
| CVE-2025-43510 | Multiple Products | Apple Multiple Products Improper Locking Vulnerability | 2026-03-20 | |
| CVE-2025-43520 | Multiple Products | Apple Multiple Products Classic Buffer Overflow Vulnerability | 2026-03-20 | |
| CVE-2025-31277 | Multiple Products | Apple Multiple Products Buffer Overflow Vulnerability | 2026-03-20 | |
| CVE-2023-43000 | Multiple Products | Apple Multiple products Use-After-Free Vulnerability | 2026-03-05 | |
| CVE-2021-30952 | Multiple Products | Apple Multiple Products Integer Overflow or Wraparound Vulnerability | 2026-03-05 | |
| CVE-2023-41974 | iOS and iPadOS | Apple iOS and iPadOS Use-After-Free Vulnerability | 2026-03-05 | |
| CVE-2026-20700 | Multiple Products | Apple Multiple Buffer Overflow Vulnerability | 2026-02-12 | |
| CVE-2025-43529 | Multiple Products | Apple Multiple Products Use-After-Free WebKit Vulnerability | 2025-12-15 | |
| CVE-2022-48503 | Multiple Products | Apple Multiple Products Unspecified Vulnerability | 2025-10-20 | |
| CVE-2025-43300 | iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability | 2025-08-21 | |
| CVE-2025-43200 | Multiple Products | Apple Multiple Products Unspecified Vulnerability | 2025-06-16 | |
| CVE-2025-31201 | Multiple Products | Apple Multiple Products Arbitrary Read and Write Vulnerability | 2025-04-17 | |
| CVE-2025-31200 | Multiple Products | Apple Multiple Products Memory Corruption Vulnerability | 2025-04-17 | |
| CVE-2025-24201 | Multiple Products | Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability | 2025-03-13 | |
| CVE-2025-24200 | iOS and iPadOS | Apple iOS and iPadOS Incorrect Authorization Vulnerability | 2025-02-12 | |
| CVE-2025-24085 | Multiple Products | Apple Multiple Products Use-After-Free Vulnerability | 2025-01-29 | |
| CVE-2024-44309 | Multiple Products | Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability | 2024-11-21 | |
| CVE-2024-44308 | Multiple Products | Apple Multiple Products Code Execution Vulnerability | 2024-11-21 | |
| CVE-2024-23225 | Multiple Products | Apple Multiple Products Memory Corruption Vulnerability | 2024-03-06 | |
| CVE-2024-23296 | Multiple Products | Apple Multiple Products Memory Corruption Vulnerability | 2024-03-06 | |
| CVE-2022-48618 | Multiple Products | Apple Multiple Products Memory Corruption Vulnerability | 2024-01-31 | |
| CVE-2024-23222 | Multiple Products | Apple Multiple Products WebKit Type Confusion Vulnerability | 2024-01-23 | |
| CVE-2023-41990 | Multiple Products | Apple Multiple Products Code Execution Vulnerability | 2024-01-08 | |
| CVE-2023-42917 | Multiple Products | Apple Multiple Products WebKit Memory Corruption Vulnerability | 2023-12-04 | |
| CVE-2023-42916 | Multiple Products | Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability | 2023-12-04 | |
| CVE-2023-42824 | iOS and iPadOS | Apple iOS and iPadOS Kernel Privilege Escalation Vulnerability | 2023-10-05 | |
| CVE-2023-41991 | Multiple Products | Apple Multiple Products Improper Certificate Validation Vulnerability | 2023-09-25 | |
| CVE-2023-41992 | Multiple Products | Apple Multiple Products Kernel Privilege Escalation Vulnerability | 2023-09-25 | |
| CVE-2023-41993 | Multiple Products | Apple Multiple Products WebKit Code Execution Vulnerability | 2023-09-25 | |
| CVE-2023-41064 | iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS ImageIO Buffer Overflow Vulnerability | 2023-09-11 | |
| CVE-2023-41061 | iOS, iPadOS, and watchOS | Apple iOS, iPadOS, and watchOS Wallet Code Execution Vulnerability | 2023-09-11 | |
| CVE-2023-38606 | Multiple Products | Apple Multiple Products Kernel Unspecified Vulnerability | 2023-07-26 | |
| CVE-2023-37450 | Multiple Products | Apple Multiple Products WebKit Code Execution Vulnerability | 2023-07-13 | |
| CVE-2023-32434 | Multiple Products | Apple Multiple Products Integer Overflow Vulnerability | 2023-06-23 | |
| CVE-2023-32435 | Multiple Products | Apple Multiple Products WebKit Memory Corruption Vulnerability | 2023-06-23 | |
| CVE-2023-32439 | Multiple Products | Apple Multiple Products WebKit Type Confusion Vulnerability | 2023-06-23 | |
| CVE-2023-32409 | Multiple Products | Apple Multiple Products WebKit Sandbox Escape Vulnerability | 2023-05-22 | |
| CVE-2023-28204 | Multiple Products | Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability | 2023-05-22 | |
| CVE-2023-32373 | Multiple Products | Apple Multiple Products WebKit Use-After-Free Vulnerability | 2023-05-22 | |
| CVE-2019-8526 | macOS | Apple macOS Use-After-Free Vulnerability | 2023-04-17 | |
| CVE-2023-28205 | Multiple Products | Apple Multiple Products WebKit Use-After-Free Vulnerability | 2023-04-10 | |
| CVE-2023-28206 | iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS IOSurfaceAccelerator Out-of-Bounds Write Vulnerability | 2023-04-10 | |
| CVE-2021-30900 | iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability | 2023-03-30 | |
| CVE-2023-23529 | Multiple Products | Apple Multiple Products WebKit Type Confusion Vulnerability | 2023-02-14 | |
| CVE-2022-42856 | iOS | Apple iOS Type Confusion Vulnerability | 2022-12-14 | |
| CVE-2022-42827 | iOS and iPadOS | Apple iOS and iPadOS Out-of-Bounds Write Vulnerability | 2022-10-25 | |
| CVE-2022-32917 | iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS Remote Code Execution Vulnerability | 2022-09-14 | |
| CVE-2020-9934 | iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS Input Validation Vulnerability | 2022-09-08 | |
| CVE-2021-31010 | iOS, macOS, watchOS | Apple iOS, macOS, watchOS Sandbox Bypass Vulnerability | 2022-08-25 | |
| CVE-2022-32894 | iOS and macOS | Apple iOS and macOS Out-of-Bounds Write Vulnerability | 2022-08-18 | |
| CVE-2022-32893 | iOS and macOS | Apple iOS and macOS Out-of-Bounds Write Vulnerability | 2022-08-18 | |
| CVE-2021-30983 | iOS and iPadOS | Apple iOS and iPadOS Buffer Overflow Vulnerability | 2022-06-27 | |
| CVE-2020-3837 | Multiple Products | Apple Multiple Products Memory Corruption Vulnerability | 2022-06-27 | |
| CVE-2020-9907 | Multiple Products | Apple Multiple Products Memory Corruption Vulnerability | 2022-06-27 | |
| CVE-2019-8605 | Multiple Products | Apple Multiple Products Use-After-Free Vulnerability | 2022-06-27 | |
| CVE-2018-4344 | Multiple Products | Apple Multiple Products Memory Corruption Vulnerability | 2022-06-27 | |
| CVE-2016-4655 | iOS | Apple iOS Information Disclosure Vulnerability | 2022-05-24 | |
| CVE-2016-4656 | iOS | Apple iOS Memory Corruption Vulnerability | 2022-05-24 | |
| CVE-2016-4657 | iOS | Apple iOS Webkit Memory Corruption Vulnerability | 2022-05-24 |
Showing the 60 most recent of 94 Apple KEV entries. Full catalog at CISA.
← All vendors by exploited-vulnerability count
🤖 Generated by defend.network from the CISA KEV catalog. Counts are deterministic aggregates of official CISA data; verify individual advisories at the linked sources.