Apple: how long users stay exposed after a fix exists
iOS, iPadOS and macOS. CVEs whose earliest fix shipped on or after 2023-01-01. Median and worst case are shown; means are not.
Export every CVE × branch row behind this page: CSV · JSON · Permalink: /apple
Branch: A major OS version line that receives its own updates, e.g. iOS 16 or macOS 14 Sonoma. iOS and iPadOS are counted separately.
First fix: The release date of the earliest Apple update (including Rapid Security Responses and Background Security Improvements) whose advisory lists the CVE.
Exploited: Listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, or Apple's advisory says the issue “may have been exploited”.
1. Backport gap for exploited flaws
How long did users of an older branch wait after the same flaw was already fixed on another branch of the same OS?
Backport gap: For one CVE and one branch: the branch's first fix date minus the earliest fix date across all branches of the same platform.
No fix listed: The branch is still maintained (it shipped a security update after the earliest fix, or its last security update is under 180 days old), but no Apple advisory lists this CVE for it as of the data date. The branch may be unaffected; Apple does not publish “not affected” statements.
Branch ended: The branch shipped no security update after the earliest fix and none in the 180 days before the data date, so it is treated as ended and not counted as missing a backport. Updates without published CVE entries do not keep a branch alive.
iOS
iOS 15, the oldest iOS branch still maintained, got fixes for exploited flaws a median of 34 days after the earliest fix (worst: 961 days, CVE-2023-43000), over 22 fixes. 21 exploited iOS CVEs have no iOS 15 fix listed. Other branches are in the table.
| Branch | Maintained | Fixed | Same day | Median gap | Worst gap | No fix listed | Branch ended |
|---|---|---|---|---|---|---|---|
| iOS 27 | yes | 0 | 0 | unknown | unknown | 1 | 0 |
| iOS 26 | yes | 6 | 6 | 0 days | 0 days (CVE-2026-86950) | 0 | 0 |
| iOS 18 | yes | 15 | 13 | 0 days | 2 days (CVE-2025-43510) | 2 | 0 |
| iOS 17 | no | 13 | 13 | 0 days | 0 days (CVE-2024-44308) | 0 | 15 |
| iOS 16 | yes | 29 | 20 | 0 days | 69 days (CVE-2024-23296) | 14 | 0 |
| iOS 15 | yes | 22 | 5 | 34 days | 961 days (CVE-2023-43000) | 21 | 0 |
| iOS 12 | no | 0 | 0 | unknown | unknown | 1 | 42 |
iPadOS
iPadOS 15, the oldest iPadOS branch still maintained, got fixes for exploited flaws a median of 34 days after the earliest fix (worst: 961 days, CVE-2023-43000), over 22 fixes. 21 exploited iPadOS CVEs have no iPadOS 15 fix listed. Other branches are in the table.
| Branch | Maintained | Fixed | Same day | Median gap | Worst gap | No fix listed | Branch ended |
|---|---|---|---|---|---|---|---|
| iPadOS 27 | yes | 0 | 0 | unknown | unknown | 1 | 0 |
| iPadOS 26 | yes | 6 | 6 | 0 days | 0 days (CVE-2026-86950) | 0 | 0 |
| iPadOS 18 | yes | 15 | 13 | 0 days | 2 days (CVE-2025-43510) | 2 | 0 |
| iPadOS 17 | yes | 19 | 17 | 0 days | 63 days (CVE-2025-24085) | 9 | 0 |
| iPadOS 16 | yes | 29 | 20 | 0 days | 69 days (CVE-2024-23296) | 14 | 0 |
| iPadOS 15 | yes | 22 | 5 | 34 days | 961 days (CVE-2023-43000) | 21 | 0 |
macOS
macOS 14 Sonoma, the oldest macOS branch still maintained, got fixes for exploited flaws a median of 0 days after the earliest fix (worst: 63 days, CVE-2025-24085), over 12 fixes. 11 exploited macOS CVEs have no macOS 14 Sonoma fix listed. Other branches are in the table.
| Branch | Maintained | Fixed | Same day | Median gap | Worst gap | No fix listed | Branch ended |
|---|---|---|---|---|---|---|---|
| macOS 27 Golden Gate | yes | 0 | 0 | unknown | unknown | 1 | 0 |
| macOS 26 Tahoe | yes | 7 | 7 | 0 days | 0 days (CVE-2026-86950) | 0 | 0 |
| macOS 15 Sequoia | yes | 14 | 14 | 0 days | 0 days (CVE-2026-86950) | 3 | 0 |
| macOS 14 Sonoma | yes | 12 | 11 | 0 days | 63 days (CVE-2025-24085) | 11 | 0 |
| macOS 13 Ventura | no | 22 | 20 | 0 days | 67 days (CVE-2024-23296) | 10 | 7 |
| macOS 12 Monterey | no | 9 | 5 | 0 days | 182 days (CVE-2023-41990) | 13 | 17 |
| macOS 11 Big Sur | no | 5 | 2 | 3 days | 182 days (CVE-2023-41990) | 9 | 25 |
2. Exploited before patch
Of the flaws known to be exploited, how many were attacked before any patch existed?
Exploited: Listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, or Apple's advisory says the issue “may have been exploited”.
36 of 44 exploited Apple flaws were attacked before a patch existed, per Apple's own advisory (“may have been exploited”). How long before is not public.
KEV date added (proxy): CISA KEV “date added” is when CISA catalogued evidence of exploitation. It is a lagging proxy: exploitation started on or before that date, usually well before.
Secondary, KEV proxy: 44 are in CISA KEV, listed a median of 3 days after the first patch (longest: 955 days, CVE-2023-43000); 2 were listed before any patch existed.
Third-party component: CISA KEV files the CVE under a vendor other than Apple (e.g. Google for Chromium code shipped in WebKit/ANGLE). The flaw is in a component Apple ships but does not own.
3 of the exploited CVEs are in third-party components.
| CVE | First fix | KEV added | KEV vs first fix | Apple: exploited at release | NVD published |
|---|---|---|---|---|---|
| CVE-2026-86950 (exploited before patch) | 1 day after | yes | |||
| CVE-2026-65400 | 12 days after | no | |||
| CVE-2026-20700 (exploited before patch) | 1 day after | yes | |||
| CVE-2025-14174 (exploited before patch) third-party component (Google) | same day | yes | |||
| CVE-2025-43529 (exploited before patch) | 3 days after | yes | |||
| CVE-2025-43510 | 137 days after | no | |||
| CVE-2025-43520 | 137 days after | no | |||
| CVE-2025-43300 (exploited before patch) | 1 day after | yes | |||
| CVE-2025-31277 | 234 days after | no | |||
| CVE-2025-6558 (exploited before patch) third-party component (Google) | 7 days before | no | |||
| CVE-2025-31200 (exploited before patch) | 1 day after | yes | |||
| CVE-2025-31201 (exploited before patch) | 1 day after | yes | |||
| CVE-2025-24201 (exploited before patch) | 2 days after | yes | |||
| CVE-2025-24200 (exploited before patch) | 2 days after | yes | |||
| CVE-2025-43200 (exploited before patch) | 126 days after | yes | |||
| CVE-2025-24085 (exploited before patch) | 2 days after | yes | |||
| CVE-2024-44308 (exploited before patch) | 2 days after | yes | |||
| CVE-2024-44309 (exploited before patch) | 2 days after | yes | |||
| CVE-2024-23225 (exploited before patch) | 1 day after | yes | |||
| CVE-2024-23296 (exploited before patch) | 1 day after | yes | |||
| CVE-2024-23222 (exploited before patch) | 1 day after | yes | |||
| CVE-2023-42916 (exploited before patch) | 4 days after | yes | |||
| CVE-2023-42917 (exploited before patch) | 4 days after | yes | |||
| CVE-2023-42824 (exploited before patch) | 1 day after | yes | |||
| CVE-2023-5217 (exploited before patch) third-party component (Google) | 2 days before | no | |||
| CVE-2023-41991 (exploited before patch) | 4 days after | yes | |||
| CVE-2023-41992 (exploited before patch) | 4 days after | yes | |||
| CVE-2023-41993 (exploited before patch) | 4 days after | yes | |||
| CVE-2023-41974 | 899 days after | no | |||
| CVE-2023-41061 (exploited before patch) | 4 days after | yes | |||
| CVE-2023-41064 (exploited before patch) | 4 days after | yes | |||
| CVE-2023-38606 (exploited before patch) | 2 days after | yes | |||
| CVE-2023-43000 | 955 days after | no | |||
| CVE-2023-37450 (exploited before patch) | 3 days after | yes | |||
| CVE-2023-32434 (exploited before patch) | 2 days after | yes | |||
| CVE-2023-32439 (exploited before patch) | 2 days after | yes | |||
| CVE-2023-28204 (exploited before patch) | 4 days after | yes | |||
| CVE-2023-32373 (exploited before patch) | 4 days after | yes | |||
| CVE-2023-32409 (exploited before patch) | 4 days after | yes | |||
| CVE-2023-28205 (exploited before patch) | 3 days after | yes | |||
| CVE-2023-28206 (exploited before patch) | 3 days after | yes | |||
| CVE-2023-32435 (exploited before patch) | 88 days after | yes | |||
| CVE-2023-23529 (exploited before patch) | 1 day after | yes | |||
| CVE-2023-41990 (exploited before patch) | 350 days after | yes |
3. Disclosure lag
How long after Apple's fix did the CVE appear in NVD, where most scanners and risk tools read it?
Disclosure lag: NVD publication date minus the earliest fix date. Negative when the CVE record was published before the fix.
Median 1 day, worst 835 days (CVE-2023-43000), over 2565 of 2565 CVEs. NVD date unknown for 0. 124 were published in NVD before the fix. 614 CVEs were added to Apple's advisory after the release that fixed them; their fix date stays the release date.
| Year | CVEs | Median lag | Worst lag | NVD unknown |
|---|---|---|---|---|
| 2023 | 567 | 35 days | 835 days (CVE-2023-43000) | 0 |
| 2024 | 548 | 1 day | 521 days (CVE-2024-40849) | 0 |
| 2025 | 709 | 0 days | 437 days (CVE-2025-24165) | 0 |
| 2026 | 741 | 0 days | 166 days (CVE-2026-20672) | 0 |