# Apple vulnerabilities & exploitation

**CISA KEV** · **Ransomware**

> As of 2026-10-05, Threadlinqs tracks 60 Apple CVEs, 44 in the CISA Known Exploited Vulnerabilities catalog, 1 used in ransomware campaigns, linked to 176 tracked threat campaigns and 12 named threat actors.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 60 Apple CVEs published between 2007-09-15 and 2026-09-15. The busiest month was 2026-04 (5 new CVEs). 44 of them (73%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 60 of 60 tracked Apple CVEs.

- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228) — CRITICAL 10 · KEV · Ransomware · EPSS 94.4% · 2021-12-10
- [CVE-2023-41064](https://intel.threadlinqs.com/cve/CVE-2023-41064) — HIGH 7.8 · KEV · EPSS 85.4% · 2023-09-07
- [CVE-2021-30860](https://intel.threadlinqs.com/cve/CVE-2021-30860) — HIGH 7.8 · KEV · EPSS 76% · 2021-08-24
- [CVE-2016-4657](https://intel.threadlinqs.com/cve/CVE-2016-4657) — HIGH 8.8 · KEV · EPSS 63.6% · 2016-08-25
- [CVE-2023-32434](https://intel.threadlinqs.com/cve/CVE-2023-32434) — HIGH 7.8 · KEV · EPSS 57.8% · 2023-06-23
- [CVE-2016-4655](https://intel.threadlinqs.com/cve/CVE-2016-4655) — MEDIUM 5.5 · KEV · EPSS 30.3% · 2016-08-25
- [CVE-2023-41993](https://intel.threadlinqs.com/cve/CVE-2023-41993) — HIGH 8.8 · KEV · EPSS 24.4% · 2023-09-21
- [CVE-2016-4656](https://intel.threadlinqs.com/cve/CVE-2016-4656) — HIGH 7.8 · KEV · EPSS 21.3% · 2016-08-25
- [CVE-2025-31200](https://intel.threadlinqs.com/cve/CVE-2025-31200) — CRITICAL 9.8 · KEV · EPSS 18.6% · 2025-04-16
- [CVE-2023-28206](https://intel.threadlinqs.com/cve/CVE-2023-28206) — HIGH 8.6 · KEV · EPSS 16.5% · 2023-04-10
- [CVE-2025-31201](https://intel.threadlinqs.com/cve/CVE-2025-31201) — CRITICAL 9.8 · KEV · EPSS 13.9% · 2025-04-16
- [CVE-2023-41991](https://intel.threadlinqs.com/cve/CVE-2023-41991) — MEDIUM 5.5 · KEV · EPSS 3.2% · 2023-09-21
- [CVE-2023-41990](https://intel.threadlinqs.com/cve/CVE-2023-41990) — HIGH 7.8 · KEV · EPSS 2.7% · 2023-09-12
- [CVE-2023-3079](https://intel.threadlinqs.com/cve/CVE-2023-3079) — HIGH 8.8 · KEV · EPSS 2.1% · 2023-06-05
- [CVE-2021-30952](https://intel.threadlinqs.com/cve/CVE-2021-30952) — HIGH 7.8 · KEV · EPSS 1.2% · 2021-08-24
- [CVE-2023-41992](https://intel.threadlinqs.com/cve/CVE-2023-41992) — HIGH 7.8 · KEV · EPSS 1.2% · 2023-09-21
- [CVE-2025-43200](https://intel.threadlinqs.com/cve/CVE-2025-43200) — MEDIUM 4.2 · KEV · EPSS 1% · 2025-06-16
- [CVE-2023-41061](https://intel.threadlinqs.com/cve/CVE-2023-41061) — HIGH 7.8 · KEV · EPSS 1% · 2023-09-07
- [CVE-2025-6554](https://intel.threadlinqs.com/cve/CVE-2025-6554) — HIGH 8.1 · KEV · EPSS 0.9% · 2025-06-30
- [CVE-2025-14174](https://intel.threadlinqs.com/cve/CVE-2025-14174) — HIGH 8.8 · KEV · EPSS 0.9% · 2025-12-12
- [CVE-2026-65400](https://intel.threadlinqs.com/cve/CVE-2026-65400) — CRITICAL 9.8 · KEV · EPSS 0.8% · 2026-08-06
- [CVE-2026-3910](https://intel.threadlinqs.com/cve/CVE-2026-3910) — HIGH 8.8 · KEV · EPSS 0.6% · 2026-03-13
- [CVE-2024-23222](https://intel.threadlinqs.com/cve/CVE-2024-23222) — HIGH 8.8 · KEV · EPSS 0.6% · 2024-01-23
- [CVE-2022-32917](https://intel.threadlinqs.com/cve/CVE-2022-32917) — HIGH 7.8 · KEV · EPSS 0.5% · 2022-09-20
- [CVE-2025-43510](https://intel.threadlinqs.com/cve/CVE-2025-43510) — HIGH 7.8 · KEV · EPSS 0.5% · 2025-12-12
- [CVE-2026-20700](https://intel.threadlinqs.com/cve/CVE-2026-20700) — HIGH 7.8 · KEV · EPSS 0.4% · 2026-02-11
- [CVE-2023-32409](https://intel.threadlinqs.com/cve/CVE-2023-32409) — HIGH 8.6 · KEV · EPSS 0.3% · 2023-06-23
- [CVE-2025-43520](https://intel.threadlinqs.com/cve/CVE-2025-43520) — MEDIUM 5.5 · KEV · EPSS 0.3% · 2025-12-12
- [CVE-2026-3909](https://intel.threadlinqs.com/cve/CVE-2026-3909) — HIGH 8.8 · KEV · EPSS 0.3% · 2026-03-13
- [CVE-2026-2441](https://intel.threadlinqs.com/cve/CVE-2026-2441) — HIGH 8.8 · KEV · EPSS 0.3% · 2026-02-13
- [CVE-2023-32435](https://intel.threadlinqs.com/cve/CVE-2023-32435) — HIGH 8.8 · KEV · EPSS 0.2% · 2023-06-23
- [CVE-2022-42856](https://intel.threadlinqs.com/cve/CVE-2022-42856) — HIGH 8.8 · KEV · EPSS 0.2% · 2022-12-15
- [CVE-2023-41974](https://intel.threadlinqs.com/cve/CVE-2023-41974) — HIGH 7.8 · KEV · EPSS 0.2% · 2024-01-10
- [CVE-2022-48503](https://intel.threadlinqs.com/cve/CVE-2022-48503) — HIGH 8.8 · KEV · EPSS 0.2% · 2023-08-14
- [CVE-2025-31277](https://intel.threadlinqs.com/cve/CVE-2025-31277) — HIGH 8.8 · KEV · EPSS 0.2% · 2025-07-30
- [CVE-2025-43529](https://intel.threadlinqs.com/cve/CVE-2025-43529) — HIGH 8.8 · KEV · EPSS 0.2% · 2025-12-17
- [CVE-2023-38606](https://intel.threadlinqs.com/cve/CVE-2023-38606) — MEDIUM 5.5 · KEV · EPSS 0.1% · 2023-07-27
- [CVE-2023-23529](https://intel.threadlinqs.com/cve/CVE-2023-23529) — HIGH 8.8 · KEV · EPSS 0.1% · 2023-02-27
- [CVE-2023-28204](https://intel.threadlinqs.com/cve/CVE-2023-28204) — MEDIUM 6.5 · KEV · EPSS 0.1% · 2023-06-23
- [CVE-2023-42917](https://intel.threadlinqs.com/cve/CVE-2023-42917) — HIGH 8.8 · KEV · EPSS 0.1% · 2023-11-30
- [CVE-2023-43000](https://intel.threadlinqs.com/cve/CVE-2023-43000) — HIGH 8.8 · KEV · EPSS 0.1% · 2025-11-05
- [CVE-2023-37450](https://intel.threadlinqs.com/cve/CVE-2023-37450) — HIGH 8.8 · KEV · EPSS 0.1% · 2023-07-27
- [CVE-2023-42916](https://intel.threadlinqs.com/cve/CVE-2023-42916) — MEDIUM 6.5 · KEV · EPSS 0% · 2023-11-30
- [CVE-2023-32373](https://intel.threadlinqs.com/cve/CVE-2023-32373) — HIGH 8.8 · KEV · EPSS 0% · 2023-06-23
- [CVE-2022-46689](https://intel.threadlinqs.com/cve/CVE-2022-46689) — HIGH 7 · EPSS 85.3% · 2022-12-15
- [CVE-2004-2687](https://intel.threadlinqs.com/cve/CVE-2004-2687) — EPSS 81% · 2007-09-23
- [CVE-2026-65414](https://intel.threadlinqs.com/cve/CVE-2026-65414) — CRITICAL 9.8 · EPSS 1% · 2026-09-14
- [CVE-2023-23514](https://intel.threadlinqs.com/cve/CVE-2023-23514) — HIGH 7.8 · EPSS 0.4% · 2023-02-27
- [CVE-2026-43760](https://intel.threadlinqs.com/cve/CVE-2026-43760) — HIGH 8.6 · EPSS 0.2% · 2026-07-27
- [CVE-2026-26127](https://intel.threadlinqs.com/cve/CVE-2026-26127) — HIGH 7.5 · EPSS 0.1% · 2026-03-10
- [CVE-2026-5858](https://intel.threadlinqs.com/cve/CVE-2026-5858) — HIGH 8.8 · EPSS 0.1% · 2026-04-08
- [CVE-2026-5286](https://intel.threadlinqs.com/cve/CVE-2026-5286) — HIGH 8.8 · EPSS 0.1% · 2026-04-01
- [CVE-2026-5859](https://intel.threadlinqs.com/cve/CVE-2026-5859) — HIGH 8.8 · EPSS 0.1% · 2026-04-08
- [CVE-2026-5284](https://intel.threadlinqs.com/cve/CVE-2026-5284) — HIGH 7.5 · EPSS 0.1% · 2026-04-01
- [CVE-2026-9110](https://intel.threadlinqs.com/cve/CVE-2026-9110) — MEDIUM 4.2 · EPSS 0.1% · 2026-05-20
- [CVE-2026-9116](https://intel.threadlinqs.com/cve/CVE-2026-9116) — MEDIUM 4.3 · EPSS 0% · 2026-05-20
- [CVE-2026-9115](https://intel.threadlinqs.com/cve/CVE-2026-9115) — MEDIUM 4.3 · EPSS 0% · 2026-05-20
- [CVE-2026-28950](https://intel.threadlinqs.com/cve/CVE-2026-28950) — MEDIUM 6.2 · EPSS 0% · 2026-04-22
- [CVE-2026-86950](https://intel.threadlinqs.com/cve/CVE-2026-86950) — HIGH 8.8 · 2026-09-28
- [CVE-2026-65388](https://intel.threadlinqs.com/cve/CVE-2026-65388) — HIGH 7.5 · 2026-09-16

## Products affected

Threadlinqs normalises CPE and CNA product records across all 60 CVEs; 11 distinct Apple products are affected. The most frequently affected:

- Macos — 51 CVEs
- Iphone Os — 35 CVEs
- Ipados — 34 CVEs
- Watchos — 21 CVEs
- Tvos — 20 CVEs
- Safari — 17 CVEs
- Visionos — 11 CVEs
- iOS and iPadOS — 6 CVEs
- Xcode — 2 CVEs
- containerization — 1 CVE
- iOS — 1 CVE

## Threat activity

176 tracked threat campaigns reference Apple products or exploit Apple CVEs; the 25 most recent are listed.

- [Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any @icloud.com Sender and Pass SPF/DKIM/DMARC](https://intel.threadlinqs.com/threat/TL-2026-2891) — MEDIUM — 2026-10-04
- [CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer](https://intel.threadlinqs.com/threat/TL-2026-2840) — HIGH — 2026-10-02
- [Atomic macOS (AMOS) Stealer Delivered via Malicious Ad Impersonating Claude Code (ClickFix-style)](https://intel.threadlinqs.com/threat/TL-2026-2916) — HIGH — 2026-10-02
- [Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) Possibly Exploited in Targeted Attacks](https://intel.threadlinqs.com/threat/TL-2026-2745) — HIGH — 2026-09-28
- [OS-Aware Phishing Kit Fans Fake iCloud Alert into ScreenConnect RMM, Apple ID, and M365 AiTM Harvesters](https://intel.threadlinqs.com/threat/TL-2026-2704) — HIGH — 2026-09-27
- [MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud Calendars as C2 Dead-Drop in Fake "Toria" Crypto Wallet Campaign](https://intel.threadlinqs.com/threat/TL-2026-2723) — HIGH — 2026-09-27
- [PamStealer macOS Infostealer Adds Live C2 with X25519 Key Exchange, Four-Method Persistence](https://intel.threadlinqs.com/threat/TL-2026-2674) — HIGH — 2026-09-26
- [MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar (SONOMAC1)](https://intel.threadlinqs.com/threat/TL-2026-2637) — HIGH — 2026-09-24
- [Macfinger ClickFix Campaign Delivers Atomic macOS Stealer (AMOS) via Fake Verification Prompts](https://intel.threadlinqs.com/threat/TL-2026-2622) — HIGH — 2026-09-23
- [Jade Sleet (North Korea) Compromises Indian IT Provider via FLATROOF and ROOFDECK macOS Backdoors](https://intel.threadlinqs.com/threat/TL-2026-2599) — HIGH — 2026-09-21
- [Trusted AI Platforms Weaponized as Malware Distribution Channels: Claude Artifacts, ChatGPT, and Grok Abused Across SectopRAT, MacSync, and AMOS Campaigns](https://intel.threadlinqs.com/threat/TL-2026-2604) — HIGH — 2026-09-21
- [FomoPeek iOS App Store Poisoning: Kernel Exploit Framework Steals Crypto Private Keys via Keychain Decryption](https://intel.threadlinqs.com/threat/TL-2026-2591) — CRITICAL — 2026-09-20
- [Apple Ships 273-CVE Coordinated Security Update Across iOS 27, macOS, watchOS, tvOS, visionOS, Safari, and Xcode — Bundles a Previously KEV-Listed Pre-Auth Screen Sharing RCE](https://intel.threadlinqs.com/threat/TL-2026-2522) — CRITICAL — 2026-09-15
- [Compromised HBO Max Reddit Account Distributes ClickFix Malware in "PasteSwitch" Cross-Platform Malvertising Campaign](https://intel.threadlinqs.com/threat/TL-2026-2506) — HIGH — 2026-09-14
- [Platform-Aware Phishing Kits Fingerprint Devices to Deliver OS-Specific RATs and Credential Harvesters](https://intel.threadlinqs.com/threat/TL-2026-2452) — HIGH — 2026-09-11
- [ClickFix Lures Deploy MacSync Stealer to Bypass macOS Security](https://intel.threadlinqs.com/threat/TL-2026-2434) — HIGH — 2026-09-10
- [QuimaRAT v2.0 — Java-Based Cross-Platform Remote Access Trojan Offered as Malware-as-a-Service](https://intel.threadlinqs.com/threat/TL-2026-2397) — HIGH — 2026-09-08
- [DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD Files with Defense Mil-Spec References](https://intel.threadlinqs.com/threat/TL-2026-2364) — CRITICAL — 2026-09-06
- [Pegasus Spyware Used to Hack Phone of Former MEP Stelios Kouloglou, PEGA Committee Member](https://intel.threadlinqs.com/threat/TL-2026-2324) — HIGH — 2026-09-04
- [Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON Steganographic Webshell in Multi-Country Espionage Campaign](https://intel.threadlinqs.com/threat/TL-2026-2325) — HIGH — 2026-09-04
- [Serbian Authorities Deploy Pegasus and NoviSpy Spyware Against Journalists, Opposition Politicians, and Student Protesters](https://intel.threadlinqs.com/threat/TL-2026-2316) — HIGH — 2026-09-03
- [Infostealer Malware (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer) Hijacking Claude Login Sessions to Drain Usage](https://intel.threadlinqs.com/threat/TL-2026-2255) — MEDIUM — 2026-08-31
- [Commodity Infostealers Hijacking Claude Login Sessions to Drain Account Usage](https://intel.threadlinqs.com/threat/TL-2026-2234) — MEDIUM — 2026-08-30
- [Threat Actors Abuse claude.ai Shared Chat Feature for ClickFix Malvertising Campaign Delivering MacSync Stealer](https://intel.threadlinqs.com/threat/TL-2026-2241) — HIGH — 2026-08-30
- [Threat Actors Abuse Trusted AI Platforms (Claude, ChatGPT, Grok) to Distribute Malware](https://intel.threadlinqs.com/threat/TL-2026-2197) — HIGH — 2026-08-29

## Threat actors targeting Apple

Named threat actors attributed to campaigns that involve Apple products or CVEs, with the number of linked campaigns:

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 9 campaigns
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 7 campaigns
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 6 campaigns
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 4 campaigns
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 4 campaigns
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 4 campaigns
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 3 campaigns
- [Intellexa Consortium](https://intel.threadlinqs.com/actor/Intellexa%20Consortium) — 3 campaigns
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 3 campaigns
- [NSO Group](https://intel.threadlinqs.com/actor/NSO%20Group) — 3 campaigns
- [UNC5342](https://intel.threadlinqs.com/actor/UNC5342) — 3 campaigns
- [UNC6353](https://intel.threadlinqs.com/actor/UNC6353) — 3 campaigns

## How to prioritise Apple patching

This order follows the data Threadlinqs holds for Apple, not a generic severity checklist:

- 44 of 60 Apple CVEs (73%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228), [CVE-2023-41064](https://intel.threadlinqs.com/cve/CVE-2023-41064), [CVE-2021-30860](https://intel.threadlinqs.com/cve/CVE-2021-30860).
- 1 CVE is known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are [CVE-2022-46689](https://intel.threadlinqs.com/cve/CVE-2022-46689) (85.3%), [CVE-2004-2687](https://intel.threadlinqs.com/cve/CVE-2004-2687) (81%), [CVE-2026-65414](https://intel.threadlinqs.com/cve/CVE-2026-65414) (1%).
- 5 CVEs score Critical and 43 High on CVSS v3 (maximum 10, average 7.9); sequence these after KEV and high-EPSS items.
- 10 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/apple
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
