PatchSiren

Apple CVE debriefs · Page 11

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited Apple CVE published 2025-04-17

CVE-2025-31200

CVE-2025-31200 is a memory corruption vulnerability affecting multiple Apple products and was added to CISA’s Known Exploited Vulnerabilities catalog on 2025-04-17. Because CISA lists it as actively exploited, organizations using Apple products should treat remediation as urgent and follow Apple’s mitigation or update guidance referenced by CISA.

Known exploited Apple CVE published 2025-03-13

CVE-2025-24201

CVE-2025-24201 is an Apple WebKit out-of-bounds write vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2025-03-13. That KEV listing makes this a priority item for defenders, even though the source corpus does not include a CVSS score or the full Apple advisory text. The remediation deadline in the KEV entry is 2025-04-03, so affected Apple environments should be reviewed and [truncated]

Known exploited Apple CVE published 2025-02-12

CVE-2025-24200

CVE-2025-24200 is an Apple iOS and iPadOS incorrect authorization issue that CISA added to its Known Exploited Vulnerabilities catalog on 2025-02-12. Because CISA flags this vulnerability for active exploitation risk, organizations should treat it as a high-priority remediation item and follow Apple’s mitigation guidance without delay.

Known exploited Apple CVE published 2025-01-29

CVE-2025-24085

CVE-2025-24085 is an Apple use-after-free vulnerability affecting multiple products. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-01-29, which means it should be treated as an urgent remediation item even though the supplied corpus does not include technical exploit details or affected-version specifics.

Known exploited Apple CVE published 2024-11-21

CVE-2024-44309

CVE-2024-44309 is an Apple cross-site scripting (XSS) vulnerability affecting multiple products and listed by CISA in the Known Exploited Vulnerabilities catalog on 2024-11-21. Because KEV inclusion indicates known exploitation, organizations should treat this as a high-priority remediation item and follow Apple’s vendor guidance for the affected products. If a specific deployment cannot be mitigated, CIS [truncated]

Known exploited Apple CVE published 2024-11-21

CVE-2024-44308

CVE-2024-44308 is a CISA Known Exploited Vulnerability affecting Apple multiple products and described as a code execution issue. Because CISA added it to the KEV catalog on 2024-11-21, defenders should treat it as an active risk rather than a theoretical one. The available source set does not include product-level technical detail or CVSS scoring, so the safest approach is to follow Apple’s vendor guidan [truncated]

Known exploited Apple CVE published 2024-03-06

CVE-2024-23296

CVE-2024-23296 is an Apple memory corruption vulnerability affecting multiple products and included in CISA’s Known Exploited Vulnerabilities catalog. The source corpus does not provide component-level detail, but KEV inclusion means defenders should treat it as actively relevant and prioritize Apple’s mitigation guidance.

Known exploited Apple CVE published 2024-03-06

CVE-2024-23225

CVE-2024-23225 is an Apple Multiple Products memory corruption vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2024-03-06. The supplied source corpus does not include product-version specifics or impact detail, but it does show CISA treating the issue as actively exploited and directing defenders to Apple’s vendor guidance for mitigation.

Known exploited Apple CVE published 2024-01-31

CVE-2022-48618

CVE-2022-48618 is an Apple memory corruption vulnerability listed by CISA in the Known Exploited Vulnerabilities (KEV) catalog. CISA added the entry on 2024-01-31 and set a remediation due date of 2024-02-21, which makes this a high-priority issue for Apple device fleets. The supplied corpus does not provide product-specific technical detail beyond the broad Apple Multiple Products classification, so the [truncated]

Known exploited Apple CVE published 2024-01-23

CVE-2024-23222

CVE-2024-23222 is an Apple WebKit type confusion vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2024-01-23. Because it is on the KEV list, defenders should treat it as actively exploited and prioritize Apple’s vendor guidance and mitigations.

Known exploited Apple CVE published 2024-01-08

CVE-2023-41990

CVE-2023-41990 is an Apple Multiple Products code execution vulnerability that CISA added to the Known Exploited Vulnerabilities (KEV) catalog on 2024-01-08. The KEV listing means the issue is considered known to be exploited in the wild, so defenders should prioritize vendor guidance and mitigation work for Apple environments that may be affected.

Known exploited Apple CVE published 2023-12-04

CVE-2023-42917

CVE-2023-42917 is a CISA Known Exploited Vulnerability affecting Apple Multiple Products and described as a WebKit memory corruption vulnerability. Because it appears in CISA's KEV catalog, defenders should treat it as urgent and follow Apple’s remediation guidance referenced by CISA. The public corpus supplied here does not include affected versions or a CVSS score, so the safest response is to prioritiz [truncated]

Known exploited Apple CVE published 2023-12-04

CVE-2023-42916

CVE-2023-42916 is an Apple WebKit out-of-bounds read vulnerability affecting multiple Apple products. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-12-04, which makes it a high-priority issue for defenders. The supplied corpus does not include a CVSS score, so prioritization here is driven by known exploitation status and vendor remediation guidance referenced by CISA.

Known exploited Apple CVE published 2023-10-05

CVE-2023-42824

CVE-2023-42824 is a CISA Known Exploited Vulnerability affecting Apple iOS and iPadOS. The public corpus identifies it as a kernel privilege escalation issue and places it in CISA’s KEV catalog on 2023-10-05, with a mitigation deadline of 2023-10-26. Treat this as a high-priority mobile endpoint risk, especially for fleets that rely on Apple devices for business access.

Known exploited Apple CVE published 2023-09-25

CVE-2023-41993

CVE-2023-41993 is an Apple WebKit code execution vulnerability affecting Apple multiple products that CISA added to its Known Exploited Vulnerabilities catalog on 2023-09-25. Because CISA lists it as actively exploited, organizations should treat it as a high-priority remediation item and follow Apple’s mitigation guidance referenced by CISA.

Known exploited Apple CVE published 2023-09-25

CVE-2023-41992

CVE-2023-41992 is an Apple kernel privilege escalation vulnerability affecting multiple products. CISA added the issue to its Known Exploited Vulnerabilities catalog on 2023-09-25 and set a remediation due date of 2023-10-16, so organizations should treat it as urgent and verify that Apple’s security updates and mitigations are in place.

Known exploited Apple CVE published 2023-09-25

CVE-2023-41991

CVE-2023-41991 is an Apple improper certificate validation vulnerability affecting multiple products. Because CISA added it to the Known Exploited Vulnerabilities catalog on 2023-09-25, this should be treated as an actively exploited issue and remediated with urgent priority.

Known exploited Apple CVE published 2023-09-11

CVE-2023-41064

CVE-2023-41064 is an Apple ImageIO buffer overflow affecting iOS, iPadOS, and macOS. CISA placed it in the Known Exploited Vulnerabilities catalog on 2023-09-11, which makes remediation urgent for organizations that manage Apple devices.

Known exploited Apple CVE published 2023-09-11

CVE-2023-41061

CVE-2023-41061 is a high-priority Apple vulnerability affecting Wallet on iOS, iPadOS, and watchOS. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-09-11, which means there is evidence of active exploitation or confirmed exploitation activity significant enough to warrant rapid remediation. CISA’s required action is to apply vendor mitigations or discontinue use of the product if miti [truncated]

Known exploited Apple CVE published 2023-07-26

CVE-2023-38606

CVE-2023-38606 is an Apple kernel unspecified vulnerability affecting multiple products and listed by CISA in the Known Exploited Vulnerabilities catalog. Because CISA marked it as actively exploited, defenders should treat it as urgent and follow the linked Apple advisories for product-specific remediation guidance.

Known exploited Apple CVE published 2023-07-13

CVE-2023-37450

CVE-2023-37450 is an Apple WebKit code execution vulnerability that CISA placed in its Known Exploited Vulnerabilities catalog on 2023-07-13. Because it is a KEV-listed issue, defenders should treat it as urgent and apply Apple’s updates as soon as possible, or stop using the affected product if updates are not available.

Known exploited Apple CVE published 2023-06-23

CVE-2023-32439

CVE-2023-32439 is a CISA Known Exploited Vulnerabilities entry tied to Apple products and identified as a WebKit type confusion issue. CISA added the CVE on 2023-06-23 and set a remediation due date of 2023-07-14. Because it appears in KEV, defenders should treat it as an active patching priority and confirm that Apple updates have been applied across in-scope devices.

Known exploited Apple CVE published 2023-06-23

CVE-2023-32435

CVE-2023-32435 is an Apple WebKit memory corruption vulnerability that CISA added to the Known Exploited Vulnerabilities (KEV) catalog on 2023-06-23. Because it appears in KEV, defenders should treat it as an active-risk issue and prioritize Apple’s updates referenced in the CISA entry.

Known exploited Apple CVE published 2023-06-23

CVE-2023-32434

CVE-2023-32434 is an Apple integer overflow vulnerability affecting multiple products. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-06-23, which makes it a high-priority remediation item for defenders. The supplied corpus does not provide affected-version detail, but it does point to Apple security update guidance and CISA’s required-action guidance: apply updates per vendor instructions.

Known exploited Apple CVE published 2023-05-22

CVE-2023-32409

CVE-2023-32409 is an Apple WebKit sandbox escape vulnerability affecting Apple multiple products. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-05-22, which means there is authoritative evidence of exploitation and a short remediation window was set by CISA for federal environments. The supplied corpus does not include affected version ranges or technical exploit details, so the saf [truncated]

Known exploited Apple CVE published 2023-05-22

CVE-2023-32373

CVE-2023-32373 is an Apple WebKit use-after-free vulnerability affecting multiple products. CISA included it in the Known Exploited Vulnerabilities catalog on 2023-05-22, which means defenders should treat it as an actively exploited issue and prioritize Apple vendor updates.

Known exploited Apple CVE published 2023-05-22

CVE-2023-28204

CVE-2023-28204 is an Apple WebKit out-of-bounds read vulnerability affecting multiple Apple products. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-05-22, so defenders should treat Apple’s updates as urgent and verify remediation across managed fleets.

Known exploited Apple CVE published 2023-04-17

CVE-2019-8526

CVE-2019-8526 is an Apple macOS use-after-free vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. Because it is on the KEV list, defenders should treat it as a patch priority and follow Apple’s update guidance. The available source data does not include a CVSS score, detailed affected-version scope, or exploit mechanics, so the safest response is to confirm exposure, apply [truncated]

Known exploited Apple CVE published 2023-04-10

CVE-2023-28206

CVE-2023-28206 is an Apple IOSurfaceAccelerator out-of-bounds write affecting iOS, iPadOS, and macOS. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-04-10, which means defenders should treat it as actively exploited and prioritize vendor updates.

Known exploited Apple CVE published 2023-04-10

CVE-2023-28205

CVE-2023-28205 is a WebKit use-after-free vulnerability affecting Apple multiple products and listed by CISA in the Known Exploited Vulnerabilities catalog. Because it is a KEV item, defenders should treat it as actively exploited and prioritize vendor updates referenced by CISA.