Exploitation timeline
Threadlinqs has recorded 60 Apple CVEs published between and . The busiest month was 2026-04 (5 new CVEs). 44 of them (73%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 60 of 60 tracked Apple CVEs.
- CVE-2021-44228critical 10KEVRansomwareEPSS 94.4%
- CVE-2023-41064high 7.8KEVEPSS 85.4%
- CVE-2021-30860high 7.8KEVEPSS 76%
- CVE-2016-4657high 8.8KEVEPSS 63.6%
- CVE-2023-32434high 7.8KEVEPSS 57.8%
- CVE-2016-4655medium 5.5KEVEPSS 30.3%
- CVE-2023-41993high 8.8KEVEPSS 24.4%
- CVE-2016-4656high 7.8KEVEPSS 21.3%
- CVE-2025-31200critical 9.8KEVEPSS 18.6%
- CVE-2023-28206high 8.6KEVEPSS 16.5%
- CVE-2025-31201critical 9.8KEVEPSS 13.9%
- CVE-2023-41991medium 5.5KEVEPSS 3.2%
- CVE-2023-41990high 7.8KEVEPSS 2.7%
- CVE-2023-3079high 8.8KEVEPSS 2.1%
- CVE-2021-30952high 7.8KEVEPSS 1.2%
- CVE-2023-41992high 7.8KEVEPSS 1.2%
- CVE-2025-43200medium 4.2KEVEPSS 1%
- CVE-2023-41061high 7.8KEVEPSS 1%
- CVE-2025-6554high 8.1KEVEPSS 0.9%
- CVE-2025-14174high 8.8KEVEPSS 0.9%
- CVE-2026-65400critical 9.8KEVEPSS 0.8%
- CVE-2026-3910high 8.8KEVEPSS 0.6%
- CVE-2024-23222high 8.8KEVEPSS 0.6%
- CVE-2022-32917high 7.8KEVEPSS 0.5%
- CVE-2025-43510high 7.8KEVEPSS 0.5%
- CVE-2026-20700high 7.8KEVEPSS 0.4%
- CVE-2023-32409high 8.6KEVEPSS 0.3%
- CVE-2025-43520medium 5.5KEVEPSS 0.3%
- CVE-2026-3909high 8.8KEVEPSS 0.3%
- CVE-2026-2441high 8.8KEVEPSS 0.3%
- CVE-2023-32435high 8.8KEVEPSS 0.2%
- CVE-2022-42856high 8.8KEVEPSS 0.2%
- CVE-2023-41974high 7.8KEVEPSS 0.2%
- CVE-2022-48503high 8.8KEVEPSS 0.2%
- CVE-2025-31277high 8.8KEVEPSS 0.2%
- CVE-2025-43529high 8.8KEVEPSS 0.2%
- CVE-2023-38606medium 5.5KEVEPSS 0.1%
- CVE-2023-23529high 8.8KEVEPSS 0.1%
- CVE-2023-28204medium 6.5KEVEPSS 0.1%
- CVE-2023-42917high 8.8KEVEPSS 0.1%
- CVE-2023-43000high 8.8KEVEPSS 0.1%
- CVE-2023-37450high 8.8KEVEPSS 0.1%
- CVE-2023-42916medium 6.5KEVEPSS 0%
- CVE-2023-32373high 8.8KEVEPSS 0%
- CVE-2022-46689high 7EPSS 85.3%
- CVE-2004-2687EPSS 81%
- CVE-2026-65414critical 9.8EPSS 1%
- CVE-2023-23514high 7.8EPSS 0.4%
- CVE-2026-43760high 8.6EPSS 0.2%
- CVE-2026-26127high 7.5EPSS 0.1%
- CVE-2026-5858high 8.8EPSS 0.1%
- CVE-2026-5286high 8.8EPSS 0.1%
- CVE-2026-5859high 8.8EPSS 0.1%
- CVE-2026-5284high 7.5EPSS 0.1%
- CVE-2026-9110medium 4.2EPSS 0.1%
- CVE-2026-9116medium 4.3EPSS 0%
- CVE-2026-9115medium 4.3EPSS 0%
- CVE-2026-28950medium 6.2EPSS 0%
- CVE-2026-86950high 8.8
- CVE-2026-65388high 7.5
Products affected
Threadlinqs normalises CPE and CNA product records across all 60 CVEs; 11 distinct Apple products are affected. The most frequently affected:
- Macos 51 CVEs
- Iphone Os 35 CVEs
- Ipados 34 CVEs
- Watchos 21 CVEs
- Tvos 20 CVEs
- Safari 17 CVEs
- Visionos 11 CVEs
- iOS and iPadOS 6 CVEs
- Xcode 2 CVEs
- containerization 1 CVE
- iOS 1 CVE
Threat activity
176 tracked threat campaigns reference Apple products or exploit Apple CVEs; the 25 most recent are listed.
- Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any @icloud.com Sender and Pass SPF/DKIM/DMARCMEDIUM
- CloudSyncD macOS Backdoor Delivered via Fake Zoom InstallerHIGH
- Atomic macOS (AMOS) Stealer Delivered via Malicious Ad Impersonating Claude Code (ClickFix-style)HIGH
- Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) Possibly Exploited in Targeted AttacksHIGH
- OS-Aware Phishing Kit Fans Fake iCloud Alert into ScreenConnect RMM, Apple ID, and M365 AiTM HarvestersHIGH
- MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud Calendars as C2 Dead-Drop in Fake "Toria" Crypto Wallet CampaignHIGH
- PamStealer macOS Infostealer Adds Live C2 with X25519 Key Exchange, Four-Method PersistenceHIGH
- MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar (SONOMAC1)HIGH
- Macfinger ClickFix Campaign Delivers Atomic macOS Stealer (AMOS) via Fake Verification PromptsHIGH
- Jade Sleet (North Korea) Compromises Indian IT Provider via FLATROOF and ROOFDECK macOS BackdoorsHIGH
- Trusted AI Platforms Weaponized as Malware Distribution Channels: Claude Artifacts, ChatGPT, and Grok Abused Across SectopRAT, MacSync, and AMOS CampaignsHIGH
- FomoPeek iOS App Store Poisoning: Kernel Exploit Framework Steals Crypto Private Keys via Keychain DecryptionCRITICAL
- Apple Ships 273-CVE Coordinated Security Update Across iOS 27, macOS, watchOS, tvOS, visionOS, Safari, and Xcode — Bundles a Previously KEV-Listed Pre-Auth Screen Sharing RCECRITICAL
- Compromised HBO Max Reddit Account Distributes ClickFix Malware in "PasteSwitch" Cross-Platform Malvertising CampaignHIGH
- Platform-Aware Phishing Kits Fingerprint Devices to Deliver OS-Specific RATs and Credential HarvestersHIGH
- ClickFix Lures Deploy MacSync Stealer to Bypass macOS SecurityHIGH
- QuimaRAT v2.0 — Java-Based Cross-Platform Remote Access Trojan Offered as Malware-as-a-ServiceHIGH
- DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD Files with Defense Mil-Spec ReferencesCRITICAL
- Pegasus Spyware Used to Hack Phone of Former MEP Stelios Kouloglou, PEGA Committee MemberHIGH
- Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON Steganographic Webshell in Multi-Country Espionage CampaignHIGH
- Serbian Authorities Deploy Pegasus and NoviSpy Spyware Against Journalists, Opposition Politicians, and Student ProtestersHIGH
- Infostealer Malware (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer) Hijacking Claude Login Sessions to Drain UsageMEDIUM
- Commodity Infostealers Hijacking Claude Login Sessions to Drain Account UsageMEDIUM
- Threat Actors Abuse claude.ai Shared Chat Feature for ClickFix Malvertising Campaign Delivering MacSync StealerHIGH
- Threat Actors Abuse Trusted AI Platforms (Claude, ChatGPT, Grok) to Distribute MalwareHIGH
Threat actors targeting Apple
Named threat actors attributed to campaigns that involve Apple products or CVEs, with the number of linked campaigns:
How to prioritise Apple patching
This order follows the data Threadlinqs holds for Apple, not a generic severity checklist:
- 44 of 60 Apple CVEs (73%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2021-44228, CVE-2023-41064, CVE-2021-30860.
- 1 CVE is known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are CVE-2022-46689 (85.3%), CVE-2004-2687 (81%), CVE-2026-65414 (1%).
- 5 CVEs score Critical and 43 High on CVSS v3 (maximum 10, average 7.9); sequence these after KEV and high-EPSS items.
- 10 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.