basicsecurity.net
Proof, not just disclosure.
Threats / Contributors / Apple
Vendor security team contributor

Apple

cited as evidence in 71 · CNA assigner on 94 of 95 known-exploited records. Every aggregate on this page is recomputed from the records listed below — each one already cited to its public source.

support.apple.com ↗ · home of the cited advisories

95
records cited in
deterministic count
0
finder / reporter credits
CVE.org credits
94
CVE records catalogued (CNA)
assigner
13%
avg modeled exploit prob.
FIRST EPSS, 95/95
0%
ransomware-associated
0 of 95 · CISA flag
R

Roles across the work

— find / fix / exploit / catalog, computed per record from credit type, the vendor-self-CNA gate, and the linked public exploit catalog
0
Find
record(s)
94
Fix
record(s)
0
Exploit
record(s)
0
Catalog
record(s)

Each dimension is a count of the listed records where this contributor did that job. A CNA row is fix only when the affected product is the assigner’s own; registries, coordinators, platforms, intel and research houses read as catalog, never fix. Exploit counts records where this contributor is credited as author of a public exploit / detection template in a linked catalog — we link the catalog, never host a payload.

01

Known for

— recomputed from this contributor’s own records
SurfacesApplication / other (55), Operating system / kernel (39), Browser (1)
WeaknessMemory safety (62), Authorization / access control (5), Web / client (2), Authentication (2), Resource / availability (1)
PortfolioApple (94), Google (1)
02

Narrative reach

— how far this contributor’s records carry an attacker, front door → lights out
1Front door
94reach this stage
→
2Keys to the kingdom
94reach this stage
→
3Lateral reach
85reach this stage
→
4Data at risk
2reach this stage
→
5Lights out
0reach this stage

Furthest any of these records carries an attacker: 4 · Data at risk. 2 of 94 narrative-framed records reach data-at-risk or lights-out. (furthest-position idiom, reused from the landing map; the stage mapping is a model output over cited evidence.)

03

Recent highlights

— this contributor’s newest known-exploited records
04

Every record they’re cited in

— all 95, each linked to its cited source

This is the evidence behind every number above. Sorted ransomware-first, then by modeled exploit probability.

CVE-2021-30860Apple76%KEVCVE-2021-30657Apple69%KEVCVE-2016-4657Apple67%KEVCVE-2023-32434Apple52%KEVCVE-2014-4404Apple49%KEVCVE-2023-41064Apple45%KEVCVE-2016-4655Apple33%KEVCVE-2021-30807Apple29%KEVCVE-2023-28205Apple27%KEVCVE-2023-41993Apple24%KEVCVE-2023-32439Apple24%KEVCVE-2016-4656Apple24%KEVCVE-2023-28206Apple23%KEVCVE-2023-32435Apple23%KEVCVE-2024-44309Apple23%KEVCVE-2025-14174Google22%KEVCVE-2020-27930Apple22%KEVCVE-2025-43300Apple22%KEVCVE-2023-37450Apple19%KEVCVE-2025-31200Apple19%KEVCVE-2023-42916Apple18%KEVCVE-2019-8605Apple18%KEVCVE-2025-24085Apple18%KEVCVE-2023-32409Apple17%KEVCVE-2020-27950Apple17%KEVCVE-2022-22620Apple16%KEVCVE-2019-8506Apple16%KEVCVE-2019-7286Apple16%KEVCVE-2020-3837Apple15%KEVCVE-2021-30883Apple15%KEVCVE-2023-28204Apple14%KEVCVE-2021-1789Apple14%KEVCVE-2025-31201Apple14%KEVCVE-2023-41991Apple13%KEVCVE-2021-30858Apple13%KEVCVE-2022-22675Apple12%KEVCVE-2023-32373Apple12%KEVCVE-2022-22587Apple12%KEVCVE-2021-30762Apple11%KEVCVE-2024-23222Apple11%KEVCVE-2021-30761Apple11%KEVCVE-2020-27932Apple10%KEVCVE-2024-44308Apple10%KEVCVE-2022-32893Apple10%KEVCVE-2015-1130Apple10%KEVCVE-2023-41992Apple10%KEVCVE-2023-23529Apple10%KEVCVE-2023-42917Apple9%KEVCVE-2025-43529Apple9%KEVCVE-2022-42856Apple9%KEVCVE-2021-1870Apple8%KEVCVE-2021-1879Apple7%KEVCVE-2021-30713Apple7%KEVCVE-2021-1871Apple7%KEVCVE-2021-30952Apple7%KEVCVE-2022-32917Apple6%KEVCVE-2021-30900Apple5%KEVCVE-2019-7287Apple5%KEVCVE-2021-30661Apple4%KEVCVE-2025-24200Apple4%KEVCVE-2021-30869Apple4%KEVCVE-2023-43000Apple4%KEVCVE-2023-41061Apple4%KEVCVE-2025-24201Apple4%KEVCVE-2021-30665Apple4%KEVCVE-2021-31010Apple4%KEVCVE-2021-30663Apple3%KEVCVE-2022-32894Apple3%KEVCVE-2022-48503Apple3%KEVCVE-2020-9934Apple3%KEVCVE-2020-9907Apple3%KEVCVE-2021-30666Apple3%KEVCVE-2021-30983Apple3%KEVCVE-2023-38606Apple3%KEVCVE-2019-6223Apple3%KEVCVE-2018-4344Apple2%KEVCVE-2020-9818Apple2%KEVCVE-2021-1782Apple2%KEVCVE-2020-9819Apple2%KEVCVE-2025-31277Apple2%KEVCVE-2024-23225Apple1%KEVCVE-2024-23296Apple1%KEVCVE-2023-41974Apple1%KEVCVE-2023-41990Apple1%KEVCVE-2026-20700Apple1%KEVCVE-2026-65400Apple1%KEVCVE-2025-43200Apple1%KEVCVE-2022-22674Apple1%KEVCVE-2022-42827Apple1%KEVCVE-2023-42824Apple1%KEVCVE-2020-9859Apple1%KEVCVE-2019-8526Apple1%KEVCVE-2022-48618Apple0%KEVCVE-2025-43520Apple0%KEVCVE-2025-43510Apple0%KEV
05

Coverage & confidence

— what this profile claims, and what it does not

Established (cited)

  • Cited in 95 known-exploited records — the list below; every one links to its public source.
  • Catalogued 94 CVE record(s) as the CNA assigner (from CVE.org).
  • Coverage gaps — stated, not hidden

  • This profile is an aggregation: it asserts only what the listed records already cite — no new external claim about the contributor is made.
  • The TYPE badge and the narrative-stage mapping are editorial (our call), labeled as such, not a sourced fact.