iPadOS
iPadOS 18.7.7
Advisory officieliPadOS 18.7.7, publié le 2026-03-24, corrige 26 CVE. Les versions antérieures restent exposées à ces vulnérabilités.
- Date de sortie
- 2026-03-24
- Fin de support
- —
- CVE corrigées
- 26
- KEV CISA
- 0
5 élevé
CVE corrigées
| CVE |
|---|
|
CVE-2026-28860
HIGH 7.5
The issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, ma… |
|
CVE-2026-28876
HIGH 7.5
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 a… |
|
CVE-2026-28865
HIGH 7.5
An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequ… |
|
CVE-2025-43376
HIGH 7.5
A logic issue was addressed with improved state management. This issue is fixed in Safari 26, iOS 18.7.7 and iPadOS 18.7.7, iOS 26 and iPadOS 26, macOS Tahoe 2… |
|
CVE-2026-20687
HIGH 7.1
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequ… |
|
CVE-2025-43534
MEDIUM 6.8
A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.2 and iPadOS 26.2. A user with physic… |
|
CVE-2026-28878
MEDIUM 6.5
A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.7, … |
|
CVE-2026-28879
MEDIUM 6.5
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequ… |
|
CVE-2026-28880
MEDIUM 6.5
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15… |
|
CVE-2026-20665
MEDIUM 6.5
This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS T… |
|
CVE-2026-20690
MEDIUM 6.5
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS… |
|
CVE-2026-20657
MEDIUM 6.5
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequo… |
|
CVE-2026-28866
MEDIUM 6.2
This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.… |
|
CVE-2026-28867
MEDIUM 6.2
This issue was addressed with improved authentication. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, mac… |
|
CVE-2026-20637
MEDIUM 6.2
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.3 and iPadOS 26.3, macOS Sequ… |
|
CVE-2025-64505
MEDIUM 6.1
[Apple ImageIO] Processing a maliciously crafted file may lead to unexpected app termination |
|
CVE-2026-28886
MEDIUM 5.9
A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS S… |
|
CVE-2026-28868
MEDIUM 5.5
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5… |
|
CVE-2026-28852
MEDIUM 5.5
A stack overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.… |
|
CVE-2026-20668
MEDIUM 5.5
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.5… |
|
CVE-2026-20643
MEDIUM 5.4
A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS, iPadO… |
|
CVE-2025-14524
MEDIUM 5.3
When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3… |
|
CVE-2026-28967
MEDIUM 4.9
A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4. An attac… |
|
CVE-2026-28871
MEDIUM 4.3
A logic issue was addressed with improved checks. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4.… |
|
CVE-2026-28861
MEDIUM 4.3
A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS T… |
|
CVE-2026-28864
LOW 3.3
This issue was addressed with improved permissions checking. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.… |
Piloter cette mise à jour iOS sur votre flotte
Appaloosa orchestre les mises à jour iOS et l'inventaire des apps de votre parc.