Ipados

Vendor:

First CVE: Feb 23, 2013 · Active for 13 years

2,017
Total CVEs
More Total CVEs than 100% of tracked products
201.7
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 34% of tracked products
3.9%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Ipados over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 23, 2013
13 years ago
Most Recent CVE
Jun 29, 2026
25 days ago

CVE Severity & Scoring

Ipados2,017 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local1,105 (54.8%)
Network780 (38.7%)
Unknown2 (0.1%)
Physical98 (4.9%)
Adjacent Network32 (1.6%)
Attack Complexity
Low1,953 (96.8%)
High62 (3.1%)
Unknown2 (0.1%)
User Interaction
None726 (36.0%)
Unknown2 (0.1%)
Required1,289 (63.9%)
Privileges Required
Low278 (13.8%)
High17 (0.8%)
None1,720 (85.3%)
Unknown2 (0.1%)

Top CVEs

Signals from CVEs in this product scope (2017 CVEs).

2,017 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Jul 28, 20228.891YESNO
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.
Aug 24, 20217.891YESNO
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a cra
Sep 28, 20238.887YESNO
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS
Jan 27, 202510.086YESYES
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15.7.7, macOS Monterey 12.6.7, w
Jun 23, 20237.886YESNO
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, iOS 18.6.2 and iPadOS
Aug 21, 202510.084YESNO
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chro
Dec 12, 20258.882YESNO
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that t
Sep 21, 20238.882YESNO
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iClo
Jun 9, 20209.882NOYES
There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corrupti
Jul 15, 20257.780NOYES

Exploit Exposure

Signals from CVEs in this product scope (2017 CVEs).

CISA KEV
79 CVEs
3.9% of CVEs· 97th percentile
Metasploit
4 CVEs
0.2% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
0.2% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (2017 CVEs).

Media Mentions

Signals from CVEs in this product scope (2017 CVEs).

Top CNAs Publishing CVEs For Ipados

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
26.046.81.9%20
18.085.70.3%00
17.056.11.7%20
16.718.849.0%10
15.0117.11.5%10
14.719.82.7%00
13.617.58.0%00
13.315.32.8%00