CVEs identified

Vulnerabilities reported to Apple and fixed.

30 vulnerabilities reported
24 CVEs assigned
59 credits in advisories
4 Apple platforms
Identifier Component Impact Platforms Published
CVE-2026-43811 Books An app may be able to modify protected parts of the file system iOS / iPadOS July 2026
CVE-2026-64746 Contacts An app may be able to add contacts without user authorization macOS iOS / iPadOS watchOS visionOS July 2026
CVE-2026-20632 Music An app may be able to access sensitive user data macOS March 2026
CVE-2026-20694 MigrationKit An app may be able to access sensitive user data macOS March 2026
Assignment pending Finder An app may be able to access sensitive user data macOS November 2025
CVE-2025-46315 Disk An app may be able to access protected user data macOS November 2025
CVE-2025-43336 SoftwareUpdate An app with root privileges may be able to access private information macOS November 2025
CVE-2025-43351 StorageKit An app may be able to access protected user data macOS November 2025
CVE-2025-43420 Dock An app may be able to access sensitive user data macOS November 2025
CVE-2025-24197 Spotlight An app may be able to access sensitive user data macOS September 2025
CVE-2025-43207 Music An app may be able to access sensitive user data macOS September 2025
CVE-2025-43288 Archive Utility An app may be able to bypass Privacy preferences macOS September 2025
CVE-2025-43315 MigrationKit An app may be able to access sensitive user data macOS September 2025
CVE-2025-24281 FeedbackLogger An app may be able to access sensitive user data macOS March 2025
CVE-2025-31187 Dock An app may be able to modify protected parts of the file system macOS March 2025
CVE-2025-24138 Spotlight A malicious app may be able to leak sensitive user information macOS January 2025
CVE-2024-54567 Siri An app may be able to access sensitive user data macOS iOS / iPadOS watchOS December 2024
CVE-2024-54520 System Settings An app may be able to overwrite arbitrary files macOS December 2024
CVE-2024-54547 Dock An app may be able to access protected user data macOS December 2024
CVE-2024-44194 Siri An app may be able to access sensitive user data macOS iOS / iPadOS watchOS visionOS October 2024
CVE-2024-27849 Core Data An app may be able to read sensitive location information macOS September 2024
CVE-2024-40791 Mail Accounts An app may be able to access information about a user's contacts macOS iOS / iPadOS September 2024
CVE-2024-44170 Siri An app may be able to access sensitive user data macOS iOS / iPadOS watchOS September 2024
CVE-2024-44190 System Settings An app may be able to read arbitrary files macOS September 2024
CVE-2024-40832 Messages An app may be able to view a contact's phone number in system logs macOS July 2024

The table lists distinct CVE identifiers. A single vulnerability fixed across several systems is credited in as many Apple advisories, bringing the total to 59 credits. Some entries correspond to vulnerabilities fixed by Apple without their identifier being published in the relevant advisory; they are listed here on the basis of the assignment communicated by Apple. Vulnerabilities still awaiting a fix are not shown.

Need an iOS or macOS audit?

Get in touch
Contact Lupus Nova