Known vulnerabilities in iPadOS 17.7 21H16

Vendor: Apple Inc.
Software: iPadOS
Version: 17.7 21H16
Software CPE: cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
Total vulnerabilities: 165
Public exploits: 8
Known exploited (KEV): 8
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting iPadOS version 17.7 21H16 iPadOS 17.7 21H16 is affected by 165 vulnerabilities: 6 critical, 25 high, 40 medium, 94 low Critical High Medium Low

Vulnerabilities (165)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU126887 - Exposure of sensitive information to an unauthorized actor
CVE-2026-28950
CWE-200 Low
No
No
26.4.2 23E261, 15.8.8 19H422, 16.7.16 20H392, 17.7.11, 18.7.8 22H352 23.04.2026 SB2026042332
SB2026042333
SB2026051211
and 2 more
#VU114314 - Out-of-bounds write
CVE-2025-43300
CWE-787 Critical
Public exploit available
Exploited
18.6.2 22G100, 15.8.5 19H394, 16.7.12 20H364, 17.7.10 20.08.2025 SB20250820136
SB20250820137
SB20250820138
and 4 more
#VU113560 - Exposure of sensitive information to an unauthorized actor
CVE-2025-31276
CWE-200 Medium
No
No
18.6 22G86, 17.7.9 31.07.2025 SB2025073151
SB2025073152
#VU113559 - Multiple Interpretations of UI Input
CVE-2025-43217
CWE-450 Low
No
No
18.6 22G86, 17.7.9 31.07.2025 SB2025073151
SB2025073152
#VU113555 - Improper input validation
CVE-2025-24224
CWE-20 Low
No
No
17.7.9, 18.5 22F76 31.07.2025 SB2025073055
SB2025051303
SB2025073152
and 4 more
#VU113534 - Type confusion
CVE-2025-7424
CWE-843 High
No
No
17.7.9, 18.6 22G86 31.07.2025 SB2025073138
SB2025073141
SB2025073142
and 13 more
#VU113521 - Permissions, Privileges, and Access Controls
CVE-2025-31279
CWE-264 Low
No
No
17.7.9 30.07.2025 SB2025073053
SB2025073054
SB2025073055
and 1 more
#VU113517 - Use After Free
CVE-2025-43222
CWE-416 Medium
No
No
17.7.9 30.07.2025 SB2025073053
SB2025073054
SB2025073055
and 1 more
#VU113512 - Memory corruption
CVE-2025-31278
CWE-119 High
No
No
17.7.9, 18.6 22G86 30.07.2025 SB2025073052
SB2025073053
SB2025073151
and 33 more
#VU113506 - Use After Free
CVE-2025-43216
CWE-416 Low
No
No
17.7.9, 18.6 22G86 30.07.2025 SB2025073053
SB2025073151
SB2025073152
and 31 more
#VU113504 - Memory corruption
CVE-2025-43211
CWE-119 Low
No
No
17.7.9, 18.6 22G86 30.07.2025 SB2025073052
SB2025073053
SB2025073151
and 30 more
#VU113482 - Information Exposure Through Log Files
CVE-2025-43225
CWE-532 Low
No
No
17.7.9 30.07.2025 SB2025073053
SB2025073054
SB2025073055
and 1 more
#VU113470 - Improper input validation
CVE-2025-43226
CWE-20 Medium
No
No
17.7.9, 18.6 22G86 30.07.2025 SB2025073053
SB2025073054
SB2025073151
and 4 more
#VU113469 - Memory corruption
CVE-2025-43209
CWE-119 Low
No
No
17.7.9, 18.6 22G86 30.07.2025 SB2025073053
SB2025073054
SB2025073055
and 5 more
#VU113461 - Improper Access Control
CVE-2025-43230
CWE-284 Low
No
No
17.7.9, 18.6 22G86 30.07.2025 SB2025073053
SB2025073151
SB2025073152
and 3 more
#VU113460 - Memory corruption
CVE-2025-43210
CWE-119 Low
No
No
17.7.9, 18.6 22G86 30.07.2025 SB2025073053
SB2025073054
SB2025073055
and 5 more
#VU113458 - Improper Link Resolution Before File Access ('Link Following')
CVE-2025-43220
CWE-59 Low
No
No
17.7.9 30.07.2025 SB2025073053
SB2025073054
SB2025073055
and 1 more
#VU113457 - Improper input validation
CVE-2025-43223
CWE-20 Low
No
No
17.7.9, 18.6 22G86 30.07.2025 SB2025073053
SB2025073054
SB2025073055
and 5 more
#VU112907 - Improper input validation
CVE-2025-6558
CWE-20 Critical
Public exploit available
Exploited
17.7.9, 18.6 22G86 15.07.2025 SB2025071542
SB2025071717
SB2025071780
and 38 more
#VU108995 - Permissions, Privileges, and Access Controls
CVE-2025-24220
CWE-264 Low
No
No
17.7.7, 17.7.9, 18.4 22E240 13.05.2025 SB2025051304
SB2025040107
SB2025073152


Showing elements 1 - 20 out of 165