Patch SLA Tracker

Apple: how long users stay exposed after a fix exists

iOS, iPadOS and macOS. CVEs whose earliest fix shipped on or after 2023-01-01. Median and worst case are shown; means are not.

Export every CVE × branch row behind this page: CSV · JSON · Permalink: /apple

Branch: A major OS version line that receives its own updates, e.g. iOS 16 or macOS 14 Sonoma. iOS and iPadOS are counted separately.

First fix: The release date of the earliest Apple update (including Rapid Security Responses and Background Security Improvements) whose advisory lists the CVE.

Exploited: Listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, or Apple's advisory says the issue “may have been exploited”.

1. Backport gap for exploited flaws

How long did users of an older branch wait after the same flaw was already fixed on another branch of the same OS?

Backport gap: For one CVE and one branch: the branch's first fix date minus the earliest fix date across all branches of the same platform.

No fix listed: The branch is still maintained (it shipped a security update after the earliest fix, or its last security update is under 180 days old), but no Apple advisory lists this CVE for it as of the data date. The branch may be unaffected; Apple does not publish “not affected” statements.

Branch ended: The branch shipped no security update after the earliest fix and none in the 180 days before the data date, so it is treated as ended and not counted as missing a backport. Updates without published CVE entries do not keep a branch alive.

iOS

iOS 15, the oldest iOS branch still maintained, got fixes for exploited flaws a median of 34 days after the earliest fix (worst: 961 days, CVE-2023-43000), over 22 fixes. 21 exploited iOS CVEs have no iOS 15 fix listed. Other branches are in the table.

iOS: backport gap per branch, exploited CVEs. Maintained: last security release under 180 days old. Branches that had ended for every CVE are omitted (see export).
BranchMaintainedFixedSame dayMedian gapWorst gapNo fix listedBranch ended
iOS 27yes00unknownunknown10
iOS 26yes660 days0 days (CVE-2026-86950)00
iOS 18yes15130 days2 days (CVE-2025-43510)20
iOS 17no13130 days0 days (CVE-2024-44308)015
iOS 16yes29200 days69 days (CVE-2024-23296)140
iOS 15yes22534 days961 days (CVE-2023-43000)210
iOS 12no00unknownunknown142
iOS backport gaps per branch, in days after the earliest fixiOS 26: 6 fixes, from 0 days to 0 days; iOS 18: 15 fixes, from 0 days to 2 days; iOS 17: 13 fixes, from 0 days to 0 days; iOS 16: 29 fixes, from 0 days to 69 days; iOS 15: 22 fixes, from 0 days to 961 days0248495743990iOS 26iOS 18iOS 17iOS 16iOS 15days after earliest fix
Each circle is one CVE. Circles at 0 were fixed the same day as the earliest fix.

iPadOS

iPadOS 15, the oldest iPadOS branch still maintained, got fixes for exploited flaws a median of 34 days after the earliest fix (worst: 961 days, CVE-2023-43000), over 22 fixes. 21 exploited iPadOS CVEs have no iPadOS 15 fix listed. Other branches are in the table.

iPadOS: backport gap per branch, exploited CVEs. Maintained: last security release under 180 days old. Branches that had ended for every CVE are omitted (see export).
BranchMaintainedFixedSame dayMedian gapWorst gapNo fix listedBranch ended
iPadOS 27yes00unknownunknown10
iPadOS 26yes660 days0 days (CVE-2026-86950)00
iPadOS 18yes15130 days2 days (CVE-2025-43510)20
iPadOS 17yes19170 days63 days (CVE-2025-24085)90
iPadOS 16yes29200 days69 days (CVE-2024-23296)140
iPadOS 15yes22534 days961 days (CVE-2023-43000)210
iPadOS backport gaps per branch, in days after the earliest fixiPadOS 26: 6 fixes, from 0 days to 0 days; iPadOS 18: 15 fixes, from 0 days to 2 days; iPadOS 17: 19 fixes, from 0 days to 63 days; iPadOS 16: 29 fixes, from 0 days to 69 days; iPadOS 15: 22 fixes, from 0 days to 961 days0248495743990iPadOS 26iPadOS 18iPadOS 17iPadOS 16iPadOS 15days after earliest fix
Each circle is one CVE. Circles at 0 were fixed the same day as the earliest fix.

macOS

macOS 14 Sonoma, the oldest macOS branch still maintained, got fixes for exploited flaws a median of 0 days after the earliest fix (worst: 63 days, CVE-2025-24085), over 12 fixes. 11 exploited macOS CVEs have no macOS 14 Sonoma fix listed. Other branches are in the table.

macOS: backport gap per branch, exploited CVEs. Maintained: last security release under 180 days old. Branches that had ended for every CVE are omitted (see export).
BranchMaintainedFixedSame dayMedian gapWorst gapNo fix listedBranch ended
macOS 27 Golden Gateyes00unknownunknown10
macOS 26 Tahoeyes770 days0 days (CVE-2026-86950)00
macOS 15 Sequoiayes14140 days0 days (CVE-2026-86950)30
macOS 14 Sonomayes12110 days63 days (CVE-2025-24085)110
macOS 13 Venturano22200 days67 days (CVE-2024-23296)107
macOS 12 Montereyno950 days182 days (CVE-2023-41990)1317
macOS 11 Big Surno523 days182 days (CVE-2023-41990)925
macOS backport gaps per branch, in days after the earliest fixmacOS 26 Tahoe: 7 fixes, from 0 days to 0 days; macOS 15 Sequoia: 14 fixes, from 0 days to 0 days; macOS 14 Sonoma: 12 fixes, from 0 days to 63 days; macOS 13 Ventura: 22 fixes, from 0 days to 67 days; macOS 12 Monterey: 9 fixes, from 0 days to 182 days; macOS 11 Big Sur: 5 fixes, from 0 days to 182 days053105158210macOS 26 TahoemacOS 15 SequoiamacOS 14 SonomamacOS 13 VenturamacOS 12 MontereymacOS 11 Big Surdays after earliest fix
Each circle is one CVE. Circles at 0 were fixed the same day as the earliest fix.

2. Exploited before patch

Of the flaws known to be exploited, how many were attacked before any patch existed?

Exploited: Listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, or Apple's advisory says the issue “may have been exploited”.

36 of 44 exploited Apple flaws were attacked before a patch existed, per Apple's own advisory (“may have been exploited”). How long before is not public.

KEV date added (proxy): CISA KEV “date added” is when CISA catalogued evidence of exploitation. It is a lagging proxy: exploitation started on or before that date, usually well before.

Secondary, KEV proxy: 44 are in CISA KEV, listed a median of 3 days after the first patch (longest: 955 days, CVE-2023-43000); 2 were listed before any patch existed.

Third-party component: CISA KEV files the CVE under a vendor other than Apple (e.g. Google for Chromium code shipped in WebKit/ANGLE). The flaw is in a component Apple ships but does not own.

3 of the exploited CVEs are in third-party components.

Exploited CVEs, newest first. Red marks exploitation documented before a patch existed.
CVEFirst fixKEV addedKEV vs first fixApple: exploited at releaseNVD published
CVE-2026-86950 (exploited before patch)1 day afteryes
CVE-2026-6540012 days afterno
CVE-2026-20700 (exploited before patch)1 day afteryes
CVE-2025-14174 (exploited before patch) third-party component (Google)same dayyes
CVE-2025-43529 (exploited before patch)3 days afteryes
CVE-2025-43510137 days afterno
CVE-2025-43520137 days afterno
CVE-2025-43300 (exploited before patch)1 day afteryes
CVE-2025-31277234 days afterno
CVE-2025-6558 (exploited before patch) third-party component (Google)7 days beforeno
CVE-2025-31200 (exploited before patch)1 day afteryes
CVE-2025-31201 (exploited before patch)1 day afteryes
CVE-2025-24201 (exploited before patch)2 days afteryes
CVE-2025-24200 (exploited before patch)2 days afteryes
CVE-2025-43200 (exploited before patch)126 days afteryes
CVE-2025-24085 (exploited before patch)2 days afteryes
CVE-2024-44308 (exploited before patch)2 days afteryes
CVE-2024-44309 (exploited before patch)2 days afteryes
CVE-2024-23225 (exploited before patch)1 day afteryes
CVE-2024-23296 (exploited before patch)1 day afteryes
CVE-2024-23222 (exploited before patch)1 day afteryes
CVE-2023-42916 (exploited before patch)4 days afteryes
CVE-2023-42917 (exploited before patch)4 days afteryes
CVE-2023-42824 (exploited before patch)1 day afteryes
CVE-2023-5217 (exploited before patch) third-party component (Google)2 days beforeno
CVE-2023-41991 (exploited before patch)4 days afteryes
CVE-2023-41992 (exploited before patch)4 days afteryes
CVE-2023-41993 (exploited before patch)4 days afteryes
CVE-2023-41974899 days afterno
CVE-2023-41061 (exploited before patch)4 days afteryes
CVE-2023-41064 (exploited before patch)4 days afteryes
CVE-2023-38606 (exploited before patch)2 days afteryes
CVE-2023-43000955 days afterno
CVE-2023-37450 (exploited before patch)3 days afteryes
CVE-2023-32434 (exploited before patch)2 days afteryes
CVE-2023-32439 (exploited before patch)2 days afteryes
CVE-2023-28204 (exploited before patch)4 days afteryes
CVE-2023-32373 (exploited before patch)4 days afteryes
CVE-2023-32409 (exploited before patch)4 days afteryes
CVE-2023-28205 (exploited before patch)3 days afteryes
CVE-2023-28206 (exploited before patch)3 days afteryes
CVE-2023-32435 (exploited before patch)88 days afteryes
CVE-2023-23529 (exploited before patch)1 day afteryes
CVE-2023-41990 (exploited before patch)350 days afteryes

3. Disclosure lag

How long after Apple's fix did the CVE appear in NVD, where most scanners and risk tools read it?

Disclosure lag: NVD publication date minus the earliest fix date. Negative when the CVE record was published before the fix.

Median 1 day, worst 835 days (CVE-2023-43000), over 2565 of 2565 CVEs. NVD date unknown for 0. 124 were published in NVD before the fix. 614 CVEs were added to Apple's advisory after the release that fixed them; their fix date stays the release date.

Disclosure lag by year of first fix
YearCVEsMedian lagWorst lagNVD unknown
202356735 days835 days (CVE-2023-43000)0
20245481 day521 days (CVE-2024-40849)0
20257090 days437 days (CVE-2025-24165)0
20267410 days166 days (CVE-2026-20672)0