iPad OS Apple iPad OS Apple iPad Operating System

Do you want an email whenever new security vulnerabilities are reported in Apple iPad OS?

Recent Apple iPad OS Security Advisories

Advisory Title Published
HT213258 iOS 15.5 and iPadOS 15.5 Security Content May 16, 2022
HT213219 iOS 15.4.1 and iPadOS 15.4.1 Security Content March 31, 2022
HT213182 iOS 15.4 and iPadOS 15.4 Security Content March 14, 2022
HT213093 iOS 15.3.1 and iPadOS 15.3.1 Security Content February 10, 2022
HT213053 iOS 15.3 and iPadOS 15.3 Security Content January 26, 2022
HT213043 iOS 15.2.1 and iPadOS 15.2.1 Security Content January 13, 2022
HT212976 iOS 15.2 and iPadOS 15.2 Security Content December 13, 2021
HT212868 iOS 14.8.1 and iPadOS 14.8.1 Security Content October 26, 2021
HT212867 iOS 15.1 and iPadOS 15.1 Security Content October 25, 2021
HT212846 iOS 15.0.2 and iPadOS 15.0.2 Security Content October 11, 2021

By the Year

In 2022 there have been 65 vulnerabilities in Apple iPad OS with an average score of 7.1 out of ten. Last year iPad OS had 237 security vulnerabilities published. Right now, iPad OS is on track to have less security vulnerabilities in 2022 than it did last year. However, the average CVE base score of the vulnerabilities in 2022 is greater by 0.17.

Year Vulnerabilities Average Score
2022 65 7.13
2021 237 6.95
2020 104 7.08
2019 33 7.54
2018 0 0.00

It may take a day or so for new iPad OS vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Apple iPad OS Security Vulnerabilities

An out-of-bounds write issue was addressed with improved bounds checking

CVE-2022-26739 7.8 - High - May 26, 2022

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. An application may be able to execute arbitrary code with kernel privileges.

Memory Corruption

An out-of-bounds write issue was addressed with improved bounds checking

CVE-2022-26740 7.8 - High - May 26, 2022

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. An application may be able to execute arbitrary code with kernel privileges.

Memory Corruption

A memory corruption issue was addressed with improved state management

CVE-2022-26744 7.8 - High - May 26, 2022

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 15.5 and iPadOS 15.5. An application may be able to execute arbitrary code with kernel privileges.

Memory Corruption

A memory corruption issue was addressed with improved input validation

CVE-2022-26751 7.8 - High - May 26, 2022

A memory corruption issue was addressed with improved input validation. This issue is fixed in iTunes 12.12.4 for Windows, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, macOS Big Sur 11.6.6, macOS Monterey 12.4. Processing a maliciously crafted image may lead to arbitrary code execution.

Memory Corruption

A use after free issue was addressed with improved memory management

CVE-2022-26757 7.8 - High - May 26, 2022

A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. An application may be able to execute arbitrary code with kernel privileges.

Dangling pointer

An out-of-bounds access issue was addressed with improved bounds checking

CVE-2022-26763 7.8 - High - May 26, 2022

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. A malicious application may be able to execute arbitrary code with system privileges.

Buffer Overflow

A memory corruption issue was addressed with improved validation

CVE-2022-26764 4.7 - Medium - May 26, 2022

A memory corruption issue was addressed with improved validation. This issue is fixed in watchOS 8.6, tvOS 15.5, macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. An attacker that has already achieved kernel code execution may be able to bypass kernel memory mitigations.

Memory Corruption

A race condition was addressed with improved state handling

CVE-2022-26765 4.7 - Medium - May 26, 2022

A race condition was addressed with improved state handling. This issue is fixed in watchOS 8.6, tvOS 15.5, macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.

Race Condition

A certificate parsing issue was addressed with improved checks

CVE-2022-26766 5.5 - Medium - May 26, 2022

A certificate parsing issue was addressed with improved checks. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. A malicious app may be able to bypass signature validation.

Improper Certificate Validation

A memory corruption issue was addressed with improved state management

CVE-2022-26771 7.8 - High - May 26, 2022

A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 8.6, tvOS 15.5, iOS 15.5 and iPadOS 15.5. A malicious application may be able to execute arbitrary code with kernel privileges.

Memory Corruption

A race condition was addressed with improved locking

CVE-2022-26701 7.5 - High - May 26, 2022

A race condition was addressed with improved locking. This issue is fixed in tvOS 15.5, macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. An application may be able to execute arbitrary code with kernel privileges.

Race Condition

A use after free issue was addressed with improved memory management

CVE-2022-26702 7.8 - High - May 26, 2022

A use after free issue was addressed with improved memory management. This issue is fixed in watchOS 8.6, tvOS 15.5, iOS 15.5 and iPadOS 15.5. An application may be able to execute arbitrary code with kernel privileges.

Dangling pointer

An access issue was addressed with additional sandbox restrictions on third-party applications

CVE-2022-26706 5.5 - Medium - May 26, 2022

An access issue was addressed with additional sandbox restrictions on third-party applications. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. A sandboxed process may be able to circumvent sandbox restrictions.

An integer overflow issue was addressed with improved input validation

CVE-2022-26711 9.8 - Critical - May 26, 2022

An integer overflow issue was addressed with improved input validation. This issue is fixed in tvOS 15.5, iTunes 12.12.4 for Windows, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.

Integer Overflow or Wraparound

A memory corruption issue was addressed with improved validation

CVE-2022-26714 7.8 - High - May 26, 2022

A memory corruption issue was addressed with improved validation. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. An application may be able to execute arbitrary code with kernel privileges.

Memory Corruption

An authorization issue was addressed with improved state management

CVE-2022-26703 2.4 - Low - May 26, 2022

An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.5 and iPadOS 15.5. A person with physical access to an iOS device may be able to access photos from the lock screen.

AuthZ

An out-of-bounds write issue was addressed with improved bounds checking

CVE-2022-22675 7.8 - High - May 26, 2022

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.3.1, iOS 15.4.1 and iPadOS 15.4.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..

Memory Corruption

This issue was addressed with improved checks to prevent unauthorized actions

CVE-2022-22663 5.5 - Medium - May 26, 2022

This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in iOS 15.4 and iPadOS 15.4, Security Update 2022-004 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.6. A malicious application may bypass Gatekeeper checks.

AuthZ

A memory corruption issue was addressed with improved memory handling

CVE-2022-22672 7.8 - High - May 26, 2022

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15.4 and iPadOS 15.4, Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. A malicious application may be able to execute arbitrary code with kernel privileges.

Memory Corruption

This issue was addressed with improved checks

CVE-2022-22673 7.5 - High - May 26, 2022

This issue was addressed with improved checks. This issue is fixed in iOS 15.5 and iPadOS 15.5. Processing a large input may lead to a denial of service.

A logic issue was addressed with improved validation

CVE-2022-22578 7.8 - High - March 18, 2022

A logic issue was addressed with improved validation. This issue is fixed in tvOS 15.3, iOS 15.3 and iPadOS 15.3, watchOS 8.4, macOS Monterey 12.2. A malicious application may be able to gain root privileges.

Improper Privilege Management

An information disclosure issue was addressed with improved state management

CVE-2022-22579 7.8 - High - March 18, 2022

An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 15.3 and iPadOS 15.3, tvOS 15.3, Security Update 2022-001 Catalina, macOS Monterey 12.2, macOS Big Sur 11.6.3. Processing a maliciously crafted STL file may lead to unexpected application termination or arbitrary code execution.

Exposure of Resource to Wrong Sphere

A memory corruption issue was addressed with improved validation

CVE-2022-22584 7.8 - High - March 18, 2022

A memory corruption issue was addressed with improved validation. This issue is fixed in tvOS 15.3, iOS 15.3 and iPadOS 15.3, watchOS 8.4, macOS Monterey 12.2. Processing a maliciously crafted file may lead to arbitrary code execution.

Memory Corruption

An issue existed within the path validation logic for symlinks

CVE-2022-22585 7.5 - High - March 18, 2022

An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, macOS Monterey 12.2, macOS Big Sur 11.6.3. An application may be able to access a user's files.

insecure temporary file

A memory corruption issue was addressed with improved input validation

CVE-2022-22587 9.8 - Critical - March 18, 2022

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, macOS Big Sur 11.6.3, macOS Monterey 12.2. A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..

Memory Corruption

A validation issue was addressed with improved input sanitization

CVE-2022-22589 6.1 - Medium - March 18, 2022

A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing a maliciously crafted mail message may lead to running arbitrary javascript.

Improper Input Validation

A cross-origin issue in the IndexDB API was addressed with improved input validation

CVE-2022-22594 6.5 - Medium - March 18, 2022

A cross-origin issue in the IndexDB API was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. A website may be able to track sensitive user information.

Origin Validation Error

A memory corruption issue was addressed with improved validation

CVE-2022-22596 7.8 - High - March 18, 2022

A memory corruption issue was addressed with improved validation. This issue is fixed in watchOS 8.5, iOS 15.4 and iPadOS 15.4. An application may be able to execute arbitrary code with kernel privileges.

Memory Corruption

An issue with app access to camera metadata was addressed with improved logic

CVE-2022-22598 3.3 - Low - March 18, 2022

An issue with app access to camera metadata was addressed with improved logic. This issue is fixed in iOS 15.4 and iPadOS 15.4. An app may be able to learn information about the current camera view before being granted camera access.

Exposure of Resource to Wrong Sphere

Description: A permissions issue was addressed with improved validation

CVE-2022-22599 2.4 - Low - March 18, 2022

Description: A permissions issue was addressed with improved validation. This issue is fixed in watchOS 8.5, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, macOS Monterey 12.3. A person with physical access to a device may be able to use Siri to obtain some location information from the lock screen.

Incorrect Permission Assignment for Critical Resource

This issue was addressed with improved checks

CVE-2022-22618 7.8 - High - March 18, 2022

This issue was addressed with improved checks. This issue is fixed in watchOS 8.5, iOS 15.4 and iPadOS 15.4. A user may be able to bypass the Emergency SOS passcode prompt.

AuthZ

This issue was addressed with improved checks

CVE-2022-22622 4.6 - Medium - March 18, 2022

This issue was addressed with improved checks. This issue is fixed in iOS 15.4 and iPadOS 15.4. A person with physical access to an iOS device may be able to see sensitive information via keyboard suggestions.

Exposure of Resource to Wrong Sphere

A buffer overflow issue was addressed with improved memory handling

CVE-2022-22593 7.8 - High - March 18, 2022

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Security Update 2022-001 Catalina, macOS Monterey 12.2, macOS Big Sur 11.6.3. A malicious application may be able to execute arbitrary code with kernel privileges.

Classic Buffer Overflow

A use after free issue was addressed with improved memory management

CVE-2022-22620 8.8 - High - March 18, 2022

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

Dangling pointer

A memory corruption issue was addressed with improved state management

CVE-2022-22633 7.8 - High - March 18, 2022

A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 8.5, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, macOS Monterey 12.3. Opening a maliciously crafted PDF file may lead to an unexpected application termination or arbitrary code execution.

Memory Corruption

The GSMA authentication panel could be presented on the lock screen

CVE-2022-22652 6.1 - Medium - March 18, 2022

The GSMA authentication panel could be presented on the lock screen. The issue was resolved by requiring device unlock to interact with the GSMA authentication panel. This issue is fixed in iOS 15.4 and iPadOS 15.4. A person with physical access may be able to view and modify the carrier account information and settings from the lock screen.

Exposure of Resource to Wrong Sphere

A logic issue was addressed with improved state management

CVE-2022-22639 7.8 - High - March 18, 2022

A logic issue was addressed with improved state management. This issue is fixed in iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. An application may be able to gain elevated privileges.

Improper Privilege Management

An out-of-bounds write was addressed with improved input validation

CVE-2021-30771 7.8 - High - March 18, 2022

An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.4, iOS 14.6 and iPadOS 14.6, watchOS 7.5, tvOS 14.6. Processing a maliciously crafted font file may lead to arbitrary code execution.

Memory Corruption

A use after free issue was addressed with improved memory management

CVE-2022-22590 8.8 - High - March 18, 2022

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing maliciously crafted web content may lead to arbitrary code execution.

Dangling pointer

A logic issue was addressed with improved state management

CVE-2022-22592 6.5 - Medium - March 18, 2022

A logic issue was addressed with improved state management. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.

A resource exhaustion issue was addressed with improved input validation

CVE-2022-22588 5.5 - Medium - March 18, 2022

A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 15.2.1 and iPadOS 15.2.1. Processing a maliciously crafted HomeKit accessory name may cause a denial of service.

Resource Exhaustion

A use after free issue was addressed with improved memory management

CVE-2022-22615 7.8 - High - March 18, 2022

A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, Security Update 2022-003 Catalina, watchOS 8.5, macOS Monterey 12.3. An application may be able to execute arbitrary code with kernel privileges.

Dangling pointer

This issue was addressed with improved checks

CVE-2022-22621 4.6 - Medium - March 18, 2022

This issue was addressed with improved checks. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3, watchOS 8.5. A person with physical access to an iOS device may be able to see sensitive information via keyboard suggestions.

Information Disclosure

A logic issue was addressed with improved state management

CVE-2022-22632 9.8 - Critical - March 18, 2022

A logic issue was addressed with improved state management. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, watchOS 8.5, macOS Monterey 12.3. A malicious application may be able to elevate privileges.

A buffer overflow was addressed with improved bounds checking

CVE-2022-22634 7.8 - High - March 18, 2022

A buffer overflow was addressed with improved bounds checking. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4. A malicious application may be able to execute arbitrary code with kernel privileges.

Classic Buffer Overflow

An out-of-bounds write issue was addressed with improved bounds checking

CVE-2022-22636 7.8 - High - March 18, 2022

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4. An application may be able to execute arbitrary code with kernel privileges.

Memory Corruption

A null pointer dereference was addressed with improved validation

CVE-2022-22638 6.5 - Medium - March 18, 2022

A null pointer dereference was addressed with improved validation. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, Security Update 2022-003 Catalina, watchOS 8.5, macOS Monterey 12.3. An attacker in a privileged position may be able to perform a denial of service attack.

NULL Pointer Dereference

A memory corruption issue was addressed with improved validation

CVE-2022-22640 7.8 - High - March 18, 2022

A memory corruption issue was addressed with improved validation. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3, watchOS 8.5. An application may be able to execute arbitrary code with kernel privileges.

Buffer Overflow

This issue was addressed with improved checks

CVE-2022-22642 9.8 - Critical - March 18, 2022

This issue was addressed with improved checks. This issue is fixed in iOS 15.4 and iPadOS 15.4. A user may be able to bypass the Emergency SOS passcode prompt.

An authentication issue was addressed with improved state management

CVE-2022-22671 4.6 - Medium - March 18, 2022

An authentication issue was addressed with improved state management. This issue is fixed in iOS 15.4 and iPadOS 15.4. A person with physical access to an iOS device may be able to access photos from the lock screen.

An out-of-bounds read was addressed with improved input validation

CVE-2022-22611 7.8 - High - March 18, 2022

An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, iTunes 12.12.3 for Windows, watchOS 8.5, macOS Monterey 12.3. Processing a maliciously crafted image may lead to arbitrary code execution.

Out-of-bounds Read

A memory consumption issue was addressed with improved memory handling

CVE-2022-22612 7.8 - High - March 18, 2022

A memory consumption issue was addressed with improved memory handling. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, iTunes 12.12.3 for Windows, watchOS 8.5, macOS Monterey 12.3. Processing a maliciously crafted image may lead to heap corruption.

Buffer Overflow

An out-of-bounds write issue was addressed with improved bounds checking

CVE-2022-22613 7.8 - High - March 18, 2022

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, Security Update 2022-003 Catalina, watchOS 8.5, macOS Monterey 12.3. An application may be able to execute arbitrary code with kernel privileges.

Memory Corruption

A use after free issue was addressed with improved memory management

CVE-2022-22614 7.8 - High - March 18, 2022

A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, Security Update 2022-003 Catalina, watchOS 8.5, macOS Monterey 12.3. An application may be able to execute arbitrary code with kernel privileges.

Dangling pointer

An out-of-bounds write issue was addressed with improved bounds checking

CVE-2022-22635 9.8 - Critical - March 18, 2022

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4. An application may be able to gain elevated privileges.

Memory Corruption

A use after free issue was addressed with improved memory management

CVE-2022-22641 9.8 - Critical - March 18, 2022

A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. An application may be able to gain elevated privileges.

Dangling pointer

A logic issue was addressed with improved restrictions

CVE-2022-22653 7.5 - High - March 18, 2022

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 15.4 and iPadOS 15.4. A malicious website may be able to access information about the user and their devices.

Improper Input Validation

A logic issue was addressed with improved state management

CVE-2022-22659 6.5 - Medium - March 18, 2022

A logic issue was addressed with improved state management. This issue is fixed in iOS 15.4 and iPadOS 15.4. An attacker in a privileged network position may be able to leak sensitive user information.

A memory corruption issue was addressed with improved validation

CVE-2022-22666 7.8 - High - March 18, 2022

A memory corruption issue was addressed with improved validation. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, watchOS 8.5. Processing a maliciously crafted image may lead to heap corruption.

Memory Corruption

The issue was addressed with additional permissions checks

CVE-2022-22609 7.5 - High - March 18, 2022

The issue was addressed with additional permissions checks. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3, watchOS 8.5. A malicious application may be able to read other applications' settings.

This issue was addressed with improved checks

CVE-2022-22643 7.5 - High - March 18, 2022

This issue was addressed with improved checks. This issue is fixed in iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. A user may send audio and video in a FaceTime call without knowing that they have done so.

A use after free issue was addressed with improved memory management

CVE-2022-22667 7.8 - High - March 18, 2022

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 15.4 and iPadOS 15.4. An application may be able to execute arbitrary code with kernel privileges.

Dangling pointer

An access issue was addressed with improved access restrictions

CVE-2022-22670 3.3 - Low - March 18, 2022

An access issue was addressed with improved access restrictions. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, watchOS 8.5. A malicious application may be able to identify what other applications a user has installed.

The issue was addressed with improved permissions logic

CVE-2022-22600 5.5 - Medium - March 18, 2022

The issue was addressed with improved permissions logic. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3, watchOS 8.5. A malicious application may be able to bypass certain Privacy preferences.

valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.

CVE-2022-23308 7.5 - High - February 26, 2022

valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.

Dangling pointer

A logic issue was addressed with improved state management

CVE-2021-30767 5.5 - Medium - December 23, 2021

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.6.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. A local user may be able to modify protected parts of the file system.

This issue was addressed with improved checks

CVE-2021-30808 5.5 - Medium - October 28, 2021

This issue was addressed with improved checks. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. A malicious application may be able to modify protected parts of the file system.

A use after free issue was addressed with improved memory management

CVE-2021-30809 8.8 - High - October 28, 2021

A use after free issue was addressed with improved memory management. This issue is fixed in Safari 15, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing maliciously crafted web content may lead to arbitrary code execution.

Dangling pointer

A memory corruption issue was addressed with improved input validation

CVE-2021-30814 7.8 - High - October 28, 2021

A memory corruption issue was addressed with improved input validation. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted image may lead to arbitrary code execution.

Memory Corruption

The issue was addressed with improved permissions logic

CVE-2021-30816 2.4 - Low - October 28, 2021

The issue was addressed with improved permissions logic. This issue is fixed in iOS 15 and iPadOS 15. An attacker with physical access to a device may be able to see private contact information.

Exposure of Resource to Wrong Sphere

A type confusion issue was addressed with improved state handling

CVE-2021-30818 8.8 - High - October 28, 2021

A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, iOS 15 and iPadOS 15, Safari 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.

Object Type Confusion

An out-of-bounds read was addressed with improved input validation

CVE-2021-30831 5.5 - Medium - October 28, 2021

An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted font may result in the disclosure of process memory.

Out-of-bounds Read

An out-of-bounds read was addressed with improved input validation

CVE-2021-30836 5.5 - Medium - October 28, 2021

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted audio file may disclose restricted memory.

Out-of-bounds Read

This issue was addressed with improved checks

CVE-2021-30840 7.8 - High - October 28, 2021

This issue was addressed with improved checks. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted dfont file may lead to arbitrary code execution.

An out-of-bounds read was addressed with improved input validation

CVE-2021-30819 5.5 - Medium - October 19, 2021

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 15 and iPadOS 15. Processing a maliciously crafted USD file may disclose memory contents.

Out-of-bounds Read

A logic issue was addressed with improved state management

CVE-2021-30826 7.5 - High - October 19, 2021

A logic issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15. In certain situations, the baseband would fail to enable integrity and ciphering protection.

This issue was addressed with improved checks

CVE-2021-30825 7.8 - High - October 19, 2021

This issue was addressed with improved checks. This issue is fixed in iOS 15 and iPadOS 15. A local attacker may be able to cause unexpected application termination or arbitrary code execution.

A logic issue was addressed with improved state management

CVE-2021-30820 9.8 - Critical - October 19, 2021

A logic issue was addressed with improved state management. This issue is fixed in iOS 14.8 and iPadOS 14.8. A remote attacker may be able to cause arbitrary code execution.

This issue was addressed with improved checks

CVE-2021-30811 5.5 - Medium - October 19, 2021

This issue was addressed with improved checks. This issue is fixed in iOS 15 and iPadOS 15, watchOS 8. A local attacker may be able to read sensitive information.

A memory corruption issue was addressed with improved memory handling

CVE-2021-30838 7.8 - High - October 19, 2021

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15 and iPadOS 15. A malicious application may be able to execute arbitrary code with system privileges on devices with an Apple Neural Engine.

A memory consumption issue was addressed with improved memory handling

CVE-2021-30837 7.8 - High - October 19, 2021

A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 15 and iPadOS 15, watchOS 8, tvOS 15. An application may be able to execute arbitrary code with kernel privileges.

A lock screen issue allowed access to contacts on a locked device

CVE-2021-30815 2.4 - Low - October 19, 2021

A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15. A local attacker may be able to view contacts from the lock screen.

Exposure of Resource to Wrong Sphere

An authorization issue was addressed with improved state management

CVE-2021-30810 4.3 - Medium - October 19, 2021

An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15, watchOS 8, tvOS 15. An attacker in physical proximity may be able to force a user onto a malicious Wi-Fi network during device setup.

AuthZ

This issue was addressed with improved checks

CVE-2021-30843 7.8 - High - October 19, 2021

This issue was addressed with improved checks. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted dfont file may lead to arbitrary code execution.

This issue was addressed with improved checks

CVE-2021-30842 7.8 - High - October 19, 2021

This issue was addressed with improved checks. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted dfont file may lead to arbitrary code execution.

This issue was addressed with improved checks

CVE-2021-30841 7.8 - High - October 19, 2021

This issue was addressed with improved checks. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted dfont file may lead to arbitrary code execution.

This issue was addressed with improved checks

CVE-2021-30835 7.8 - High - October 19, 2021

This issue was addressed with improved checks. This issue is fixed in Security Update 2021-005 Catalina, iTunes 12.12 for Windows, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted image may lead to arbitrary code execution.

A memory corruption issue was addressed with improved memory handling

CVE-2021-30846 7.8 - High - October 19, 2021

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.

Memory Corruption

Multiple memory corruption issues were addressed with improved memory handling

CVE-2021-30849 7.8 - High - October 19, 2021

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, watchOS 8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, iTunes 12.12 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.

Memory Corruption

A memory corruption issue was addressed with improved memory handling

CVE-2021-30848 7.8 - High - October 19, 2021

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, iOS 15 and iPadOS 15. Processing maliciously crafted web content may lead to code execution.

Memory Corruption

This issue was addressed with improved checks

CVE-2021-30847 7.8 - High - October 19, 2021

This issue was addressed with improved checks. This issue is fixed in watchOS 8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, iTunes 12.12 for Windows. Processing a maliciously crafted image may lead to arbitrary code execution.

A memory corruption issue was addressed with improved state management

CVE-2021-30665 8.8 - High - September 08, 2021

A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 7.4.1, iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

Memory Corruption

A memory corruption issue was addressed with improved validation

CVE-2021-1809 7.5 - High - September 08, 2021

A memory corruption issue was addressed with improved validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A malicious application may be able to read restricted memory.

Out-of-bounds Read

A logic issue was addressed with improved validation

CVE-2021-30667 5.4 - Medium - September 08, 2021

A logic issue was addressed with improved validation. This issue is fixed in iOS 14.6 and iPadOS 14.6. An attacker in WiFi range may be able to force a client to use a less secure authentication mechanism.

authentification

This issue was addressed with improved checks

CVE-2021-30674 5.5 - Medium - September 08, 2021

This issue was addressed with improved checks. This issue is fixed in iOS 14.6 and iPadOS 14.6. A malicious application may disclose restricted memory.

This issue was addressed with improved environment sanitization

CVE-2021-30677 8.8 - High - September 08, 2021

This issue was addressed with improved environment sanitization. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave, macOS Big Sur 11.4, watchOS 7.5. A malicious application may be able to break out of its sandbox.

This issue was addressed with improved checks

CVE-2021-30707 8.8 - High - September 08, 2021

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted audio file may lead to arbitrary code execution.

Classic Buffer Overflow

A memory corruption issue was addressed with improved state management

CVE-2021-30710 7.1 - High - September 08, 2021

A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. A malicious application may cause a denial of service or potentially disclose memory contents.

Memory Corruption

An out-of-bounds read was addressed with improved bounds checking

CVE-2021-30695 5.5 - Medium - September 08, 2021

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted USD file may disclose memory contents.

Out-of-bounds Read

A memory corruption issue was addressed with improved validation

CVE-2021-1808 7.5 - High - September 08, 2021

A memory corruption issue was addressed with improved validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. An application may be able to read restricted memory.

Out-of-bounds Read

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Apple Watch OS or by Apple? Click the Watch button to subscribe.

Apple
Vendor

Apple iPad OS
Apple iPad Operating System

subscribe