CVE Tools

Apple

8,502 CVEs tracked since 1999. Since Apr 2021, 78 of them reached CISA KEV.

Apple CVEs per month

Apr 2021 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Apple CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-041305
2021-0560
2021-0630
2021-0730
2021-081548
2021-092188
2021-10471
2021-11null or fewer
2021-12311
2022-01120
2022-02130
2022-03822
2022-04100
2022-05922
2022-0680
2022-0771
2022-08152
2022-09721
2022-1040
2022-11951
2022-12511
2023-01null or fewer
2023-02561
2023-03null or fewer
2023-0492
2023-05710
2023-06737
2023-07572
2023-08191
2023-091237
2023-10412
2023-11null or fewer
2023-12350
2024-01843
2024-02270
2024-03912
2024-0460
2024-05300
2024-06410
2024-07800
2024-08null or fewer
2024-09910
2024-10840
2024-1172
2024-12620
2025-011021
2025-0241
2025-031591
2025-04262
2025-05790
2025-06null or fewer
2025-07853
2025-0891
2025-09830
2025-1060
2025-111131
2025-12684
2026-01140
2026-02751
2026-03890
2026-04160
2026-051000
2026-06520
2026-071670
2026-08441
2026-092460

Products

The products that kept showing up in Apple's monthly top three, with their CVEs summed over those months.

  1. macOS3,15155 months
  2. iPadOS1,50838 months
  3. iPhone OS1,28937 months
  4. iOS and iPadOS1,06729 months
  5. Mac OS X1615 months
  6. Visionos262 months
  7. IOS103 months
  8. Apple M132 months
  9. Swiftnio Http\/231 month
  10. Xcode32 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Apple.

  1. CVE-2026-65388A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim's registry credentials to that host. T...7.5
  2. CVE-2026-65409A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7...5.5
  3. CVE-2026-84559A permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A malicious application may be able to access restrict...5.5
  4. CVE-2026-28960A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. A remote attacker may be able to cause a denial-of-service.7.5
  5. CVE-2026-43741A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access protected user data.5.5
  6. CVE-2026-28937This issue was addressed through improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to access sensitive user data.5.5
  7. CVE-2026-86876An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Taho...5.2
  8. CVE-2026-84518This issue was addressed through improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27. A malicious website may be able to determine what apps a us...4.3
  9. CVE-2026-84631This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27. An app may be able to gain root privileges.7.8
  10. CVE-2026-84563A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.7.5
  11. CVE-2026-84534A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visi...5.5
  12. CVE-2026-43690A race condition was addressed with improved locking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A local user may be able to read kernel memory.4.7
  13. CVE-2026-84522A race condition was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to access sensitive user data.5.9
  14. CVE-2026-86909A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to bypass Gatekeeper checks.4.4
  15. CVE-2026-43686A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26...8.8

The record

Peak rank
#1 in Sep 2021
Busiest month shown
Sep 2026, 246 CVEs
Months with a KEV entry
32 since Apr 2021
Monthly snapshots
255 since 1999
Apple's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store