Apple visionOS

116 known vulnerabilities in Apple visionOS, 9 critical, 15 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2026-20700 CVSS 7.8 high · actively exploited Apple Multiple Buffer Overflow Vulnerability
  • CVE-2025-43529 CVSS 8.8 high · actively exploited Apple Multiple Products Use-After-Free WebKit Vulnerability
  • CVE-2025-43520 CVSS 5.5 medium · actively exploited Apple Multiple Products Classic Buffer Overflow Vulnerability
  • CVE-2025-43510 CVSS 7.8 high · actively exploited Apple Multiple Products Improper Locking Vulnerability
  • CVE-2025-31277 CVSS 8.8 high · actively exploited Apple Multiple Products Buffer Overflow Vulnerability
  • CVE-2025-43200 CVSS 4.2 medium · actively exploited Apple Multiple Products Unspecified Vulnerability
  • CVE-2025-31201 CVSS 9.8 critical · actively exploited Apple Multiple Products Arbitrary Read and Write Vulnerability
  • CVE-2025-31200 CVSS 9.8 critical · actively exploited Apple Multiple Products Memory Corruption Vulnerability
  • CVE-2025-24201 CVSS 10.0 critical · actively exploited Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability
  • CVE-2025-24085 CVSS 10.0 critical · actively exploited Apple Multiple Products Use-After-Free Vulnerability

Latest vulnerabilities

  • CVE-2026-86905 CVSS 5.5 medium This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27…
  • CVE-2026-86903 CVSS 5.5 medium An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27…
  • CVE-2026-86898 CVSS 5.4 medium A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27…
  • CVE-2026-86897 CVSS 5.5 medium This issue was addressed with additional entitlement checks. This issue is fixed in Safari 27, iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS…
  • CVE-2026-86895 CVSS 7.5 high An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27…
  • CVE-2026-86893 CVSS 3.3 low A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watchOS…
  • CVE-2026-86892 CVSS 5.5 medium This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27…
  • CVE-2026-86888 CVSS 3.3 low A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS…
  • CVE-2026-86887 CVSS 3.3 low A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS…
  • CVE-2026-86883 CVSS 5.5 medium A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 27 and iPadOS 27, visionOS 27. An app may be…
  • CVE-2026-86882 CVSS 6.5 medium An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and…
  • CVE-2026-86881 CVSS 9.1 critical A certificate validation issue was addressed with improved certificate validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27…
  • CVE-2026-86876 CVSS 5.2 medium An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and…
  • CVE-2026-86870 CVSS 6.5 medium A heap buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27…
  • CVE-2026-84636 CVSS 5.5 medium An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27…
  • CVE-2026-84635 CVSS 6.5 medium A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27…
  • CVE-2026-84632 CVSS 7.3 high The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden…
  • CVE-2026-84630 CVSS 4.7 medium A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS…
  • CVE-2026-84629 CVSS 7.5 high This issue was addressed with additional entitlement checks. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watchOS…
  • CVE-2026-84628 CVSS 5.5 medium An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27…
  • CVE-2026-84626 CVSS 3.3 low An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and…
  • CVE-2026-84625 CVSS 9.1 critical A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27…
  • CVE-2026-84624 CVSS 5.5 medium A permissions issue was addressed with improved path validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27…
  • CVE-2026-84622 CVSS 6.2 medium A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and…
  • CVE-2026-84620 CVSS 7.3 high An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27…
  • CVE-2026-84616 CVSS 5.5 medium A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27…
  • CVE-2026-84615 CVSS 5.5 medium An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS…
  • CVE-2026-84612 CVSS 5.5 medium An authorization issue was addressed with improved access control. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27…
  • CVE-2026-84611 CVSS 7.3 high An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and…
  • CVE-2026-84609 CVSS 9.8 critical A permissions issue was addressed with improved path validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS…