Technology · Apple
Apple Iphone Os vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 165 vulnerabilities in Apple Iphone Os: 0 in the last 7 days and 91 in the last 90 days, 10 of them critical and 2 exploited in the wild. The most recent, CVE-2026-91742, was published on 15 September 2026.
- Last 7 days
- 0
- Last 90 days
- 91
- Critical, all time
- 10
- Exploited in the wild
- 2
About Apple Iphone Os
A mobile operating system developed by Apple for iPhone and iPod Touch devices.
Latest Apple Iphone Os vulnerabilities
- CVE-2026-91742: Google Chrome iOS PriceTracking confused deputy bypassmediumCVSS 4.8EPSS 0.2%
- CVE-2026-86924: Apple iOS and iPadOS memory corruption via malicious accessorymediumCVSS 5.5EPSS 0.2%
- CVE-2026-86905: Apple Keychain unauthorized credential deletion vulnerabilitymediumCVSS 5.5EPSS 0.1%
- CVE-2026-86904: Apple iOS iPadOS watchOS cross-app tracking privacy issuehighCVSS 7.5EPSS 0.4%
- CVE-2026-86903: Apple iOS out-of-bounds read in kernel memorymediumCVSS 5.5EPSS 0.2%
- CVE-2026-86898: Apple Safari universal cross-site scripting in webarchive handlingmediumCVSS 5.4EPSS 0.3%
- CVE-2026-86897: Apple Accessibility entitlement check bypass in iOS and macOSmediumCVSS 5.5EPSS 0.2%
- CVE-2026-86895: Apple CloudKit information disclosure in persistent account identifiershighCVSS 7.5EPSS 0.5%
- CVE-2026-86893: Apple iOS/iPadOS/tvOS/visionOS/watchOS permissions issue in CloudKitlowCVSS 3.3EPSS 0.1%
- CVE-2026-86892: Apple iOS entitlement validation denial of servicemediumCVSS 5.5EPSS 0.1%
- CVE-2026-86890: Apple iOS and iPadOS logic issue in locked device accessmediumCVSS 4.6EPSS 0.2%
- CVE-2026-86888: Apple App Store permissions issue allowing persistent account identifier exposurelowCVSS 3.3EPSS 0.1%
- CVE-2026-86887: Apple iOS privacy issue allowing app bypass of user preferenceslowCVSS 3.3EPSS 0.2%
- CVE-2026-86886: Apple iOS path traversal in system file accessmediumCVSS 5.5EPSS 0.2%
- CVE-2026-86885: Apple iOS input validation issue in wireless radio componentmediumCVSS 6.5EPSS 0.3%
- CVE-2026-86884: Apple iOS and iPadOS App Store permissions issuemediumCVSS 5.5EPSS 0.1%
- CVE-2026-86883: Apple iOS Accessibility privacy issue in file handlingmediumCVSS 5.5EPSS 0.1%
- CVE-2026-86879: Apple iOS and iPadOS input validation denial-of-servicemediumCVSS 6.5EPSS 0.4%
- CVE-2026-86878: Apple iOS and iPadOS permissions issue allowing sensitive data accessmediumCVSS 5.5EPSS 0.1%
- CVE-2026-86870: Apple iOS, iPadOS, macOS, visionOS, watchOS heap buffer overflow in Accelerate FrameworkmediumCVSS 6.5EPSS 0.4%
- CVE-2026-86869: Apple Accelerate Framework out-of-bounds write in image processingmediumCVSS 6.5EPSS 0.3%
- CVE-2026-84636: Apple iOS authorization bypass in state managementmediumCVSS 5.5EPSS 0.1%
- CVE-2026-84635: Apple Safari logic issue in state managementmediumCVSS 6.5EPSS 0.4%
- CVE-2026-84629: Apple iOS and iPadOS user fingerprinting vulnerabilityhighCVSS 7.5EPSS 0.4%
- CVE-2026-84628: Apple iOS Keychain access bypass in AccountsmediumCVSS 5.5EPSS 0.2%
Most severe Apple Iphone Os vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-31277: Apple Multiple Products memory corruption in web content processingcriticalexploited in the wildCVSS 8.8EPSS 1.5%
- CVE-2022-2294: WebRTC Heap Buffer Overflow Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2025-6965: SQLite memory corruption via aggregate term overflowcriticalCVSS 9.8EPSS 64.9%
- CVE-2026-30783: RustDesk Client privilege abuse via unauthenticated strategy injectioncriticalCVSS 9.8EPSS 0.6%
- CVE-2026-30789: RustDesk Client authentication bypass via session replay and weak hashingcriticalCVSS 9.8EPSS 0.4%
- CVE-2026-78935: Google Chrome use of uninitialized variable in MobilecriticalCVSS 9.6EPSS 0.5%
- CVE-2026-85047: Google Chrome improper input validation in Transactions Platform on iOScriticalCVSS 9.6EPSS 0.5%
- CVE-2026-78964: Google Chrome use after free in Sync on iOScriticalCVSS 9.6EPSS 0.5%
- CVE-2026-87609: Google Chrome use-after-free in Sharing on iOScriticalCVSS 9.6EPSS 0.4%
- CVE-2026-84625: Apple iOS permissions issue allowing user fingerprintingcriticalCVSS 9.1EPSS 0.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 12 | 0 | |
| 24 Aug 2026 | 9 | 2 | |
| 31 Aug 2026 | 1 | 1 | |
| 7 Sep 2026 | 5 | 1 | |
| 14 Sep 2026 | 64 | 1 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/iphone-os.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Apple Iphone Os vulnerabilities", https://junglewise.ai/threats/technologies/iphone-os, 26 September 2026.