cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2024-23225,https://securityvulnerability.io/vulnerability/CVE-2024-23225,Apple Addresses Memory Corruption Issue in iOS and iPadOS,"A memory corruption issue affecting Apple's iOS and iPadOS products has been identified, resulting from insufficient validation mechanisms in kernel memory operations. Attackers possessing the ability to perform arbitrary reading and writing to kernel memory may potentially bypass existing memory protections. Apple has implemented fixes in iOS 16.7.6 and iPadOS 16.7.6, as well as in iOS 17.4 and iPadOS 17.4, to mitigate this vulnerability. There are reports indicating that this issue may have been actively exploited, necessitating immediate attention from users and administrators to update their systems to the latest versions.",Apple,iOS And iPad OS,7.8,HIGH,0.0020699999295175076,true,2024-03-06T00:00:00.000Z,true,false,true,2024-03-06T00:00:00.000Z,,true,true,2024-03-12T02:52:02.218Z,2024-03-05T19:24:12.330Z,14432 CVE-2024-27804,https://securityvulnerability.io/vulnerability/CVE-2024-27804,"Apple Fixes Memory Handling Issue in iOS 17.5, iPadOS 17.5, tvOS 17.5, watchOS 10.5, macOS Sonoma 14.5","A notable memory handling issue has been identified in Apple’s operating systems, which can potentially allow an application to execute arbitrary code with kernel privileges. This vulnerability may exploit the way memory is managed within the affected products, complicating security for users. The issue has been addressed in updates for iOS, iPadOS, tvOS, watchOS, and macOS, emphasizing the importance of timely software updates to mitigate risks associated with such vulnerabilities.",Apple,"iOS And iPad OS,Mac OS,Watch OS,TV OS",5.5,MEDIUM,0.0005000000237487257,false,,true,false,true,2024-05-14T02:03:55.000Z,,true,true,2024-05-14T14:52:02.815Z,2024-05-14T15:13:00.000Z,61191 CVE-2024-27815,https://securityvulnerability.io/vulnerability/CVE-2024-27815,"Apple Fixes Out-of-Bounds Write Issue in iOS 17.5, Other Platforms Affected","An out-of-bounds write vulnerability exists in various Apple operating systems where improper input validation may allow a malicious application to execute arbitrary code with kernel privileges. This issue has been addressed in several software updates, significantly enhancing the security posture of devices running affected versions. The updates aim to mitigate the risk of unauthorized access and potential exploitation, ensuring a safer environment for users.",Apple,"iOS And iPad OS,Mac OS,Visionos,Watch OS,TV OS",7.8,HIGH,0.0005699999746866524,false,,true,false,true,2024-06-20T07:03:02.000Z,true,true,true,2024-06-25T14:52:03.016Z,2024-06-10T20:56:39.364Z,3534 CVE-2025-24085,https://securityvulnerability.io/vulnerability/CVE-2025-24085,Use After Free Vulnerability in Apple VisionOS and iOS Products,"A memory management flaw classified as a use after free vulnerability has been identified in Apple's software architecture. Malicious applications may exploit this vulnerability to elevate privileges, posing a significant risk to user security. While Apple has implemented fixes in specific versions of its operating systems, reports indicate that this vulnerability might have been actively exploited in earlier versions of iOS, particularly those prior to iOS 17.2. Users are strongly advised to update their devices to the latest versions to mitigate potential risks associated with this vulnerability.",Apple,"Visionos,TV OS,Mac OS,Watch OS,iOS And iPad OS",7.8,HIGH,0.0020800000056624413,true,2025-01-29T00:00:00.000Z,true,true,true,2025-01-28T03:25:30.000Z,true,true,true,2025-01-30T18:52:02.453Z,2025-01-27T21:45:46.555Z,10318 CVE-2025-24118,https://securityvulnerability.io/vulnerability/CVE-2025-24118,Memory Handling Issue in Apple iPadOS and macOS Products,"This vulnerability relates to how memory is handled in Apple's iPadOS and macOS operating systems. An attacker may exploit this flaw to cause unexpected system termination or potentially write to kernel memory, leading to significant software instability and possible unauthorized access to sensitive information. Improvements in memory management have been implemented in the latest updates to mitigate these risks, emphasizing the importance of keeping systems up-to-date.",Apple,"Mac OS,iPad OS",9.8,CRITICAL,0.00044999999227002263,false,,false,false,true,2025-01-30T09:10:44.000Z,true,true,false,,2025-01-27T21:45:58.119Z,3987 CVE-2024-44243,https://securityvulnerability.io/vulnerability/CVE-2024-44243,Apple Addresses File System Configuration Issue with macOS Sequoia 15.2 Update,"A configuration issue in Apple macOS Sequoia allows certain applications the ability to modify protected parts of the file system, potentially exposing critical system components and data to unauthorized changes. This vulnerability emphasizes the importance of maintaining strict access controls and ensuring that security practices are in place to protect system integrity. The issue has been addressed in macOS Sequoia 15.2, underscoring the need for users to update their systems to mitigate the risks associated with this configuration flaw.",Apple,Mac OS,5.5,MEDIUM,0.00044999999227002263,false,,true,true,true,2025-01-13T16:49:06.000Z,,true,false,,2024-12-12T02:15:00.000Z,3075 CVE-2024-54492,https://securityvulnerability.io/vulnerability/CVE-2024-54492,"Apple Addresses Network Traffic Alteration Vulnerability in macOS Sequoia 15.2, iOS 18.2, and iPadOS 18.2","This vulnerability concerns a security flaw in Apple's operating systems that could allow an attacker positioned within a privileged network to intercept and manipulate network traffic. The issue arises from the application's failure to utilize HTTPS efficiently when transmitting sensitive information across the network. As a consequence, there is a risk of exposure to man-in-the-middle attacks, potentially compromising the integrity of user data. Apple has addressed this vulnerability in macOS Sequoia 15.2, iOS 18.2, iPadOS 18.2, iPadOS 17.7.3, and visionOS 2.2 by enhancing the handling of network communications.",Apple,"Visionos,Mac OS,iPad OS,iOS And iPad OS",5.9,MEDIUM,0.000539999979082495,false,,false,false,false,,,true,false,,2024-12-12T02:15:00.000Z,8186 CVE-2024-44308,https://securityvulnerability.io/vulnerability/CVE-2024-44308,"Apple Addresses Web Content Execution Vulnerability in Safari, macOS Sequoia, iOS, iPadOS, and visionOS","A vulnerability exists within Apple Safari and various iOS products that allows for arbitrary code execution via specially crafted web content. The flaw was addressed with improved checks to mitigate the exploitation risk. Apple has released security updates for affected products including Safari, iOS, iPadOS, and macOS Sequoia versions, noting that there are indications this vulnerability may have been actively exploited on Intel-based Mac systems. Users are strongly encouraged to update their devices to the latest versions to enhance security.",Apple,"Safari,Mac OS,iOS And iPad OS,Visionos",8.8,HIGH,0.0017999999690800905,true,2024-11-21T00:00:00.000Z,true,false,true,2024-11-21T00:00:00.000Z,,true,false,,2024-11-20T00:15:00.000Z,4878 CVE-2024-44258,https://securityvulnerability.io/vulnerability/CVE-2024-44258,Handling of Symlinks Improved to Address Security Risks,"A vulnerability related to symlink handling has been identified in certain Apple products, which poses a risk of modification to protected system files when a specially crafted backup file is restored. This issue has been addressed in the latest versions of iOS, iPadOS, visionOS, and tvOS, including iOS 18.1 and iPadOS 18.1. Customers are encouraged to update their devices to the latest version to mitigate potential security risks associated with this improper handling.",Apple,"Visionos,iOS And iPad OS,TV OS",7.1,HIGH,0.0004400000034365803,false,,false,false,true,2024-10-29T18:45:03.000Z,true,true,false,,2024-10-28T21:15:00.000Z,3166 CVE-2024-44133,https://securityvulnerability.io/vulnerability/CVE-2024-44133,Privacy Bypass Vulnerability Affects macOS Sequoia MDM Managed Devices,"A vulnerability has been identified in Apple’s macOS Sequoia that allows certain applications to bypass established privacy preferences on devices managed by Mobile Device Management (MDM) systems. The issue is addressed in macOS Sequoia 15, effectively removing the vulnerable code and enhancing the security framework. This flaw may pose risks to user data privacy and overall system integrity, necessitating prompt updates to the latest software version for mitigation.",Apple,Mac OS,5.5,MEDIUM,0.0004299999854993075,false,,true,false,true,2024-10-18T21:26:11.000Z,,true,false,,2024-09-17T00:15:00.000Z,5861