iPadOS

Apple · current 27

Are you Apple? Claim this page

The current version of iPadOS is 27 (as of 14/09/2026). patchletter checks the official source daily and emails you new releases.

Actively exploited vulnerabilities

The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.

  • CVE-2025-43300Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability

    10.0 critical · over the network, without login · CISA deadline was 11 Sept 25

  • CVE-2021-1871Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 17 Nov 21

  • CVE-2021-1870Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 17 Nov 21

  • CVE-2020-9818Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability

    8.8 high · over the network, without login, needs user action · CISA deadline was 3 May 22

  • CVE-2021-30858Apple iOS, iPadOS, macOS Use-After-Free Vulnerability

    8.8 high · over the network, without login, needs user action · CISA deadline was 17 Nov 21

  • CVE-2022-22620Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability

    8.8 high · over the network, without login, needs user action · CISA deadline was 25 Feb 22

  • CVE-2023-28206Apple iOS, iPadOS, and macOS IOSurfaceAccelerator Out-of-Bounds Write Vulnerability

    8.6 high · locally only, without login, needs user action · CISA deadline was 1 May 23

  • CVE-2021-30869Apple iOS, iPadOS, and macOS Type Confusion Vulnerability

    7.8 high · locally only, without login, needs user action · CISA deadline was 17 Nov 21

  • CVE-2021-30983Apple iOS and iPadOS Buffer Overflow Vulnerability

    7.8 high · locally only, without login, needs user action · CISA deadline was 18 Jul 22

  • CVE-2022-32917Apple iOS, iPadOS, and macOS Remote Code Execution Vulnerability

    7.8 high · locally only, with a basic account · CISA deadline was 5 Oct 22

  • CVE-2022-42827Apple iOS and iPadOS Out-of-Bounds Write Vulnerability

    7.8 high · locally only, without login, needs user action · CISA deadline was 15 Nov 22

  • CVE-2021-30900Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability

    7.8 high · locally only, without login, needs user action · CISA deadline was 20 Apr 23

  • CVE-2023-41061Apple iOS, iPadOS, and watchOS Wallet Code Execution Vulnerability

    7.8 high · locally only, without login, needs user action · CISA deadline was 2 Oct 23

  • CVE-2023-41064Apple iOS, iPadOS, and macOS ImageIO Buffer Overflow Vulnerability

    7.8 high · locally only, without login, needs user action · CISA deadline was 2 Oct 23

  • CVE-2023-42824Apple iOS and iPadOS Kernel Privilege Escalation Vulnerability

    7.8 high · locally only, with a basic account · CISA deadline was 26 Oct 23

  • CVE-2023-41974Apple iOS and iPadOS Use-After-Free Vulnerability

    7.8 high · locally only, without login, needs user action · CISA deadline was 26 Mar

  • CVE-2021-1879Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability

    6.1 medium · over the network, without login, needs user action · CISA deadline was 17 Nov 21

  • CVE-2025-24200Apple iOS and iPadOS Incorrect Authorization Vulnerability

    6.1 medium · with physical access only, without login · CISA deadline was 5 Mar 25

  • CVE-2020-9934Apple iOS, iPadOS, and macOS Input Validation Vulnerability

    5.5 medium · locally only, with a basic account · CISA deadline was 29 Sept 22

  • CVE-2020-9819Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability

    4.3 medium · over the network, without login, needs user action · CISA deadline was 3 May 22

Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.

BSI security advisories

Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.

All BSI advisories →

iPadOS at a glance

iPadOS has been its own branch alongside iOS since 2019 — same cadence, same version numbers, but distinct features for multitasking, Stage Manager and external displays. For update planning that means iPhone and iPad stay on matching versions while their hardware cut-offs can differ.

Operationally, iPads are usually managed through the same MDM as iPhones, often as shared devices on shift rotations, in logistics or at the point of sale. That is exactly where a forced update without a maintenance window gets expensive — deferral windows and fixed deadlines matter more here than on personal devices.

Worth checking with every major: which models are still covered. Older iPads often lose the current major earlier than iPhones of the same generation and then sit on a security branch that eventually ends.

Support cycles (endoflife.date)

CycleLatest versionStatus
2727supported
2626.7supported
1818.7.10supported
1717.7.11supported
1616.7.16supported
1515.8.8supported
1414.8.1End of Life
1313.6End of Life

Version history & changelog · as detected by patchletter

VersionChannelDateNotes
27STABLE14/09/2026
26.6.2STABLE08/09/2026
26.6.1STABLE17/08/2026
26.6STABLE27/07/2026

Frequently asked questions

What is the latest version of iPadOS?
iPadOS 27, released 14/09/2026. patchletter checks the vendor's official source daily for new releases.
Where can I find the iPadOS release notes?
The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
How do I get notified about new iPadOS updates?
Tick iPadOS off in the catalogue and leave your address. From then on new versions go out by email — one at a time, or bundled in the daily or weekly digest.

An email as soon as a new iPadOS version ships

We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.

Embed this badge

The badge shows the current iPadOS version and keeps it up to date. Anyone may embed it, no account needed.

iPadOS badge
[![iPadOS](https://patchletter.com/badge/ipados.svg)](https://patchletter.com/en/software/ipados)
https://patchletter.com/badge/ipados.svg

Also available: ?v=eol (end of support) and ?v=cve (actively exploited).

Related tools in Operating Systems