Apple Inc.

First CVE: Jan 20, 2010Active for: 17 years
6,889
CVEs Published
More CVEs Published than 97% of tracked CNAs
405.2
Avg CVEs / Year
More Avg CVEs / Year than 97% of tracked CNAs
6.8
Avg CVSS Score
Higher Avg CVSS Score than 32% of tracked CNAs
1.4%
In CISA KEV
Higher KEV Rate than 89% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Apple Inc. as a CNA, 99.6% affect products that Apple Inc. develops as a vendor.

99.6%
Self-reported: 6,864Third-party: 25

Of all the CVEs published that affect products developed by Apple Inc., 46.4% are self-published by Apple Inc. as a CNA.

46.4%
53.6%
Self-published: 6,864Published by other CNAs: 7,917

Trends Over Time

The number and severity of CVEs published by Apple Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 20, 2010
16 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs

All CVEs published by Apple Inc. as a CNA, regardless of affected vendor or product.

6,889 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
Aug 25, 20168.896YESYES
Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context via an application that pro
Sep 18, 20147.892YESYES
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekee
Sep 8, 20215.591YESYES
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.
Aug 24, 20217.891YESNO
The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
Aug 25, 20167.887YESYES
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
Aug 25, 20165.587YESYES
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS
Jan 27, 202510.086YESYES
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15.7.7, macOS Monterey 12.6.7, w
Jun 23, 20237.886YESNO
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, iOS 18.6.2 and iPadOS
Aug 21, 202510.084YESNO
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that t
Sep 21, 20238.882YESNO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA6,889 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCriticalUnknown
Attack Vector
Local2,945 (42.7%)
Network1,947 (28.3%)
Unknown1,774 (25.8%)
Physical177 (2.6%)
Adjacent Network46 (0.7%)
Attack Complexity
Low4,926 (71.5%)
High189 (2.7%)
Unknown1,774 (25.8%)
User Interaction
None1,903 (27.6%)
Unknown1,774 (25.8%)
Required3,212 (46.6%)
Privileges Required
Low826 (12.0%)
High55 (0.8%)
None4,234 (61.5%)
Unknown1,774 (25.8%)

Exploit Exposure

Signals from CVEs in this cna scope (6889 CVEs).

CISA KEV
93 CVEs
1.4% of CVEs· 89th percentile
Metasploit
37 CVEs
0.5% of CVEs· 83rd percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
301 CVEs
4.4% of CVEs· 94th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Apple Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Apple Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs