Where
AND
-Infinity
0
Severity
3.3
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Mail. The issue was resolved by clearing application previews when content is deleted.

1 / 2
First published (updated )
Severity
3.3
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Icons. The issue was addressed with improved handling of icon caches.

1 / 2
First published (updated )
Severity
3.3
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Mail. This issue was addressed with improved setting propagation.

1 / 2
First published (updated )
Severity
2.4
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Messages. An inconsistent user interface issue was addressed with improved state management.

1 / 2
First published (updated )
Severity
3.3
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Messages. This issue was addressed with improved checks.

1 / 2
First published (updated )
Severity
2.4
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Phone. A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management.

1 / 2
First published (updated )
Severity
3.3
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Quick Look. An issue existed when checking the tel URL before initiating calls. This issue was addressed with the addition of a confirmation prompt.

1 / 2
First published (updated )
Severity
2.4
Infoleak
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Accounts. A prompt management issue was addressed by removing iCloud authentication prompts from the lock screen.

1 / 2
First published (updated )
Severity
3.3
Infoleak, SQL Injection
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Safari. An issue existed in SQLite deletion. This issue was addressed through improved SQLite cleanup.

1 / 2
First published (updated )
Severity
2.4
Input Validation
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Wi-Fi. An issue existed with handling user input that caused a device to present the home screen even when activation locked. This was addressed through improved input validation.

1 / 2
First published (updated )
Severity
2.4
Input Validation, Null Pointer Dereference, Use After Free, Buffer Overflow, Integer Overflow
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Accessibility. A logging issue was addressed with improved data redaction.

1 / 48
Source: Apple
First published (updated )
Severity
2.4
Input Validation, Buffer Overflow, Integer Overflow, Race Condition, Infoleak
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Accessibility. This issue was addressed by restricting options offered on a locked device.

1 / 83
Source: Apple
First published (updated )
Severity
2.3
Input Validation, Integer Overflow, Buffer Overflow, Race Condition
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. A malicious app with root privileges may be able to access keyboard input and location information without user consent.

1 / 78
Source: MITRE
First published (updated )
Severity
3.3
Input Validation, Buffer Overflow, Race Condition, Integer Overflow, Infoleak
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Accounts. The issue was addressed with improved checks.

1 / 44
Source: Apple
First published (updated )
Severity
3.3
Input Validation, Buffer Overflow, Race Condition, Integer Overflow
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Accounts. The issue was addressed with improved checks.

1 / 34
Source: Apple
First published (updated )
Severity
3.3
Input Validation, Race Condition
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.5 and iPadOS 17.5. An app may be able to access Notes attachments.

1 / 28
Source: NVD
First published (updated )
Severity
2.4
Input Validation, Race Condition
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Apple Neural Engine. The issue was addressed with improved memory handling.

1 / 27
Source: Apple
First published (updated )
Severity
2.4
Race Condition, Input Validation
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Apple Neural Engine. The issue was addressed with improved memory handling.

1 / 32
Source: Apple
First published (updated )
Severity
2.4
Race Condition, Input Validation
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

A permissions issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access may be able to share items from the lock screen.

1 / 29
Source: MITRE
First published (updated )
Severity
3.3
Race Condition, Buffer Overflow, Input Validation, Infoleak
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Accessibility. A privacy issue was addressed with improved private data redaction for log entries.

1 / 63
Source: Apple
First published (updated )
Severity
3.3
Buffer Overflow
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Accessibility. A privacy issue was addressed with improved private data redaction for log entries.

1 / 23
Source: Apple
First published (updated )
Severity
3.3
Buffer Overflow, Race Condition
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

A logic issue was addressed with improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4. A user's locked tabs may be briefly visible while switching tab groups when Locked Private Browsing is enabled.

1 / 24
Source: MITRE
First published (updated )
Severity
3.3
Buffer Overflow, Race Condition, Input Validation
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

A privacy issue was addressed by not logging contents of text fields. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An app may be able to view Mail data.

1 / 68
Source: MITRE
First published (updated )
Severity
2.4
Buffer Overflow, Race Condition
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Accessibility. A privacy issue was addressed with improved private data redaction for log entries.

1 / 19
Source: Apple
First published (updated )
Severity
2.8
Input Validation, Buffer Overflow, Integer Overflow, Race Condition
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

A clickjacking issue was addressed with improved out-of-process view handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to trick a user into granting access to photos from the user's photo library.

1 / 89
Source: MITRE
First published (updated )
Severity
2.4
Input Validation, Race Condition, Integer Overflow, Buffer Overflow, Infoleak
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Accessibility. This issue was addressed by restricting options offered on a locked device.

1 / 35
Source: Apple
First published (updated )
Severity
3.3
EPSS
0.04%
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Accessibility. An authentication issue was addressed with improved state management.

1 / 2
Source: Apple
First published (updated )
Severity
2.4
Input Validation, Race Condition
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Apple Neural Engine. The issue was addressed with improved memory handling.

1 / 34
Source: Apple
First published (updated )
Severity
2.4
Use After Free, Input Validation
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Accessibility. The issue was addressed with improved authentication.

1 / 31
Source: Apple
First published (updated )
Severity
3.3
Input Validation, Null Pointer Dereference, Use After Free
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3. Photos in the Hidden Photos Album may be viewed without authentication.

1 / 24
Source: MITRE
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203