apple
1,466 known vulnerabilities affecting apple products.
Products
macos 1342
iphone_os 402
ipados 306
visionos 178
watchos 160
tvos 158
safari 66
mac_os_x 4
container 2
swift-crypto 2
swiftnio 1
swiftnio_http\/2 1
swiftnio_ssh 1
swiftnio_ssl 1
servicetalk 1
xcode 1
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-48287 | Medium | 0.2% | 7.4 | CAI Content Credentials is affected by an Untrusted Search Path vulnerability th… | |
| CVE-2026-11306 | Medium | 0.2% | 8.8 | Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-11670 | Medium | 0.2% | 8.8 | Use after free in PDF in Google Chrome prior to 149.0.7827.103 allowed a remote … | |
| CVE-2026-5817 | Medium | 0.2% | 8.2 | The vllm-metal inference backend in Docker Model Runner on macOS unconditionally… | |
| CVE-2026-5843 | Medium | 0.2% | 8.2 | The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM librar… | |
| CVE-2026-9958 | Medium | 0.2% | 8.8 | Use after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remo… | |
| CVE-2026-21281 | Medium | 0.2% | 7.8 | InCopy versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Ove… | |
| CVE-2026-9877 | Medium | 0.2% | 8.3 | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remot… | |
| CVE-2026-11635 | Medium | 0.2% | 8.3 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allo… | |
| CVE-2026-11663 | Medium | 0.2% | 8.3 | Use after free in Skia in Google Chrome prior to 149.0.7827.103 allowed a remote… | |
| CVE-2026-27278 | Medium | 0.2% | 7.8 | Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are… | |
| CVE-2026-9925 | Medium | 0.2% | 8.3 | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remot… | |
| CVE-2026-9931 | Medium | 0.2% | 8.3 | Use after free in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote … | |
| CVE-2026-9933 | Medium | 0.2% | 7.5 | Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remot… | |
| CVE-2026-9936 | Medium | 0.2% | 8.3 | Use after free in GFX in Google Chrome on Mac prior to 148.0.7778.216 allowed a … | |
| CVE-2026-9948 | Medium | 0.2% | 8.3 | Use after free in Views in Google Chrome on Mac prior to 148.0.7778.216 allowed … | |
| CVE-2026-9951 | Medium | 0.2% | 8.3 | Use after free in UI in Google Chrome prior to 148.0.7778.216 allowed a remote a… | |
| CVE-2026-10003 | Medium | 0.2% | 7.5 | Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remot… | |
| CVE-2026-10009 | Medium | 0.2% | 7.5 | Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remo… | |
| CVE-2026-11149 | Medium | 0.2% | 7.5 | Insufficient validation of untrusted input in Extensions in Google Chrome prior … | |
| CVE-2026-11151 | Medium | 0.2% | 7.5 | Insufficient validation of untrusted input in Password Manager in Google Chrome … | |
| CVE-2026-11239 | Medium | 0.2% | 7.5 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.… | |
| CVE-2026-17855 | Medium | 0.2% | 9.6 | Race in DevTools in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote… | |
| CVE-2026-27309 | Medium | 0.2% | 7.8 | Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free… | |
| CVE-2026-64740 | Medium | 0.2% | 9.3 | A parsing issue in the handling of directory paths was addressed with improved p… | |
| CVE-2026-21321 | Medium | 0.2% | 7.8 | After Effects versions 25.6 and earlier are affected by an Integer Overflow or W… | |
| CVE-2026-21322 | Medium | 0.2% | 7.8 | After Effects versions 25.6 and earlier are affected by an out-of-bounds read vu… | |
| CVE-2026-21324 | Medium | 0.2% | 7.8 | After Effects versions 25.6 and earlier are affected by an out-of-bounds read vu… | |
| CVE-2026-21325 | Medium | 0.2% | 7.8 | After Effects versions 25.6 and earlier are affected by an out-of-bounds read vu… | |
| CVE-2026-21330 | Medium | 0.2% | 7.8 | After Effects versions 25.6 and earlier are affected by an Access of Resource Us… | |
| CVE-2026-11231 | Medium | 0.2% | 8.1 | Inappropriate implementation in Safe Browsing in Google Chrome on Mac prior to 1… | |
| CVE-2026-11689 | Medium | 0.2% | 8.1 | Insufficient policy enforcement in Passwords in Google Chrome prior to 149.0.782… | |
| CVE-2026-48348 | Medium | 0.2% | 7.7 | Animate is affected by an Incorrect Authorization vulnerability that could resul… | |
| CVE-2026-9887 | Medium | 0.2% | 8.8 | Use after free in Proxy in Google Chrome prior to 148.0.7778.216 allowed a remot… | |
| CVE-2026-11079 | Medium | 0.2% | 8.8 | Insufficient validation of untrusted input in Codecs in Google Chrome prior to 1… | |
| CVE-2026-11198 | Medium | 0.2% | 9.6 | Insufficient validation of untrusted input in Codecs in Google Chrome prior to 1… | |
| CVE-2026-11207 | Medium | 0.2% | 9.6 | Insufficient validation of untrusted input in Autofill in Google Chrome prior to… | |
| CVE-2026-47304 | Medium | 0.2% | 8.1 | Improper verification of cryptographic signature in .NET allows an unauthorized … | |
| CVE-2026-11667 | Medium | 0.2% | 7.5 | Out of bounds read in WebRTC in Google Chrome prior to 149.0.7827.103 allowed a … | |
| CVE-2026-5912 | Medium | 0.2% | 8.8 | Integer overflow in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a rem… | |
| CVE-2026-11690 | Medium | 0.2% | 7.5 | Out of bounds read and write in Media in Google Chrome on Mac prior to 149.0.782… | |
| CVE-2026-11694 | Medium | 0.2% | 7.5 | Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed… | |
| CVE-2026-43771 | Medium | 0.2% | 7.1 | A stack overflow was addressed with improved input validation. This issue is fix… | |
| CVE-2026-9954 | Medium | 0.2% | 7.5 | Use after free in TabStrip in Google Chrome prior to 148.0.7778.216 allowed a re… | |
| CVE-2026-9970 | Medium | 0.2% | 8.3 | Use after free in WebGL in Google Chrome prior to 148.0.7778.216 allowed a remot… | |
| CVE-2026-9975 | Medium | 0.2% | 8.3 | Out of bounds read and write in ANGLE in Google Chrome prior to 148.0.7778.216 a… | |
| CVE-2026-43670 | Medium | 0.2% | 8.8 | A Content Security Policy bypass was addressed with improved enforcement in Audi… | |
| CVE-2026-43772 | Medium | 0.2% | 8.2 | A path traversal issue was addressed with improved input validation. This issue … | |
| CVE-2026-81975 | Medium | 0.2% | 7.8 | Acrobat Reader is affected by a Use After Free vulnerability that could result i… | |
| CVE-2026-11256 | Medium | 0.2% | 8.3 | Integer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote… |