How long are Apple users exposed after a security fix exists?
Three numbers for iPhone, iPad and Mac, for flaws first fixed since 2023-01-01. Checked every 6 hours against Apple's advisories, the CISA Known Exploited Vulnerabilities catalog, and NVD. Each number links to its evidence.
iOS 15, the oldest iPhone branch Apple still patches, got fixes for exploited flaws a median of 34 days after Apple's first fix.
Worst case: 961 days (CVE-2023-43000). Based on 22 fixes; 21 exploited flaws have no iOS 15 fix listed. Every branch
Backport gap: For one CVE and one branch: the branch's first fix date minus the earliest fix date across all branches of the same platform.
36 of 44 exploited Apple flaws were attacked before a patch existed, per Apple.
CISA's exploited-vulnerability catalog listed them a median of 3 days after Apple's first patch; 2 of 44 were listed before any patch existed. Details
Exploited: Listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, or Apple's advisory says the issue “may have been exploited”.
NVD published Apple CVEs a median of 1 day after Apple's fix.
Worst case: 835 days (CVE-2023-43000). NVD date unknown for 0 of 2565 CVEs. Details
Disclosure lag: NVD publication date minus the earliest fix date. Negative when the CVE record was published before the fix.