APPLE·CVE

Every Apple security advisory since 2002 — parsed, indexed, charted.

loading source ↗
Unique CVEs per year
CVEs per platforma CVE counts once per platform
Operating system shareof per-platform CVE fixes
Year shareunique CVEs, first-fix year
CVSS severityCVSS base score (NVD)
Platform × yearunique CVEs fixed
Shared fixesCVEs fixed in both platforms
Top components
Top reportersanonymous & Apple excluded
Top organisations
Impact classheuristic, from Apple's “Impact:” text
CVSS score distributionscored CVEs
OS versionsby major release
Exploited in the wildper year
Patch lagmedian days behind the first fix · CVEs fixed on 2+ platforms
Report to fixmedian days from “reported to Apple” to the first fix · where known
Added to advisories later“Entry added …” after release, per year
click a row to filter by that reporter · click an affiliation to filter by it
click a row to filter by that component
Am I affected?

Pick what you run. Lists the CVEs Apple fixed after that version — in later updates of the same version line, and fixes that only shipped in newer major versions. Based on Apple's advisories only; a CVE fixed only in a newer major version may or may not affect older ones.

CVEs with a known “reported to Apple” date — from the Project Zero issue tracker, ZDI advisories’ disclosure timelines and write-up timelines (only a fraction of all CVEs). Days are counted to Apple’s first published fix. All filters apply.

Days to fixdistribution
Median days to fix per yearby first-fix year
Per platformmedian days, report → fix on that platform
Timelineeach line: reported → first fix · dots: later fixes on other platforms · newest 80 (hover for details)
Per componentmedian days, components with 5+ CVEs
Per sourcewhere the report date comes from
click a row for details
click a row to filter by that advisory
decrypting advisories