Technology · Apple
Apple visionOS vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 291 vulnerabilities in Apple visionOS: 0 in the last 7 days and 184 in the last 90 days, 22 of them critical and 15 exploited in the wild. The most recent, CVE-2026-86905, was published on 14 September 2026.
- Last 7 days
- 0
- Last 90 days
- 184
- Critical, all time
- 22
- Exploited in the wild
- 15
About Apple visionOS
A spatial operating system developed by Apple for the Vision Pro headset.
Latest Apple visionOS vulnerabilities
- CVE-2026-86905: Apple Keychain unauthorized credential deletion vulnerabilitymediumCVSS 5.5EPSS 0.1%
- CVE-2026-86903: Apple iOS out-of-bounds read in kernel memorymediumCVSS 5.5EPSS 0.2%
- CVE-2026-86898: Apple Safari universal cross-site scripting in webarchive handlingmediumCVSS 5.4EPSS 0.3%
- CVE-2026-86897: Apple Accessibility entitlement check bypass in iOS and macOSmediumCVSS 5.5EPSS 0.2%
- CVE-2026-86895: Apple CloudKit information disclosure in persistent account identifiershighCVSS 7.5EPSS 0.5%
- CVE-2026-86893: Apple iOS/iPadOS/tvOS/visionOS/watchOS permissions issue in CloudKitlowCVSS 3.3EPSS 0.1%
- CVE-2026-86892: Apple iOS entitlement validation denial of servicemediumCVSS 5.5EPSS 0.1%
- CVE-2026-86888: Apple App Store permissions issue allowing persistent account identifier exposurelowCVSS 3.3EPSS 0.1%
- CVE-2026-86887: Apple iOS privacy issue allowing app bypass of user preferenceslowCVSS 3.3EPSS 0.2%
- CVE-2026-86883: Apple iOS Accessibility privacy issue in file handlingmediumCVSS 5.5EPSS 0.1%
- CVE-2026-86882: Apple Accelerate Framework out-of-bounds write in image processingmediumCVSS 6.5EPSS 0.5%
- CVE-2026-86881: Apple iOS, iPadOS, and macOS certificate validation bypasscriticalCVSS 9.1EPSS 0.4%
- CVE-2026-86876: Apple Accelerate Framework out-of-bounds write in image processingmediumCVSS 5.2EPSS 0.1%
- CVE-2026-86870: Apple iOS, iPadOS, macOS, visionOS, watchOS heap buffer overflow in Accelerate FrameworkmediumCVSS 6.5EPSS 0.4%
- CVE-2026-84636: Apple iOS authorization bypass in state managementmediumCVSS 5.5EPSS 0.1%
- CVE-2026-84635: Apple Safari logic issue in state managementmediumCVSS 6.5EPSS 0.4%
- CVE-2026-84632: Apple iOS and macOS 3D model memory corruptionhighCVSS 7.3EPSS 0.2%
- CVE-2026-84630: Apple iOS, iPadOS, and macOS race condition in state handlingmediumCVSS 4.7EPSS 0.1%
- CVE-2026-84629: Apple iOS and iPadOS user fingerprinting vulnerabilityhighCVSS 7.5EPSS 0.4%
- CVE-2026-84628: Apple iOS Keychain access bypass in AccountsmediumCVSS 5.5EPSS 0.2%
- CVE-2026-84626: Apple iOS and iPadOS information disclosure via app enumerationlowCVSS 3.3EPSS 0.1%
- CVE-2026-84625: Apple iOS permissions issue allowing user fingerprintingcriticalCVSS 9.1EPSS 0.5%
- CVE-2026-84624: Apple iOS, iPadOS, and macOS permissions bypass via path validationmediumCVSS 5.5EPSS 0.2%
- CVE-2026-84622: Apple iOS and iPadOS kernel memory disclosure via uninitialized memorymediumCVSS 6.2EPSS 0.2%
- CVE-2026-84620: Apple iOS and macOS integer overflow in 3D model processinghighCVSS 7.3EPSS 0.2%
Most severe Apple visionOS vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-24201: Apple Multiple Products WebKit Out-of-Bounds Write Vulnerabilitycriticalexploited in the wildCVSS 10
- CVE-2025-24085: Apple Multiple Products Use-After-Free Vulnerabilitycriticalexploited in the wildCVSS 10
- CVE-2025-31201: Apple Multiple Products Arbitrary Read and Write Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2025-31200: Apple Multiple Products Memory Corruption Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2025-31277: Apple Multiple Products memory corruption in web content processingcriticalexploited in the wildCVSS 8.8EPSS 1.5%
- CVE-2025-43529: Apple WebKit use-after-free in multiple productscriticalexploited in the wildCVSS 8.8EPSS 0.2%
- CVE-2024-44308: Apple Multiple Products Code Execution Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2024-23222: Apple Multiple Products WebKit Type Confusion Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2026-20700: Apple Multiple Operating Systems Buffer Overflowcriticalexploited in the wildCVSS 7.8EPSS 0.4%
- CVE-2025-43510: Apple Multiple Products improper locking in shared memorycriticalexploited in the wildCVSS 7.8EPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 65 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 22 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 97 | 5 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/visionos.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Apple visionOS vulnerabilities", https://junglewise.ai/threats/technologies/visionos, 26 September 2026.