Apple iOS vulnerabilities
479 known vulnerabilities affecting apple/ios.
Total CVEs
479
CISA KEV
18
actively exploited
Public exploits
36
Exploited in wild
19
Severity breakdown
CRITICAL32HIGH288MEDIUM132LOW27
Vulnerabilities
Page 2 of 24
CVE-2022-32864MEDIUMCVSS 5.5≥ unspecified, < 162022-09-20
CVE-2022-32864 [MEDIUM] CVE-2022-32864: The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6, i
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to disclose kernel memory.
cvelistv5nvd
CVE-2022-32883MEDIUMCVSS 5.5≥ unspecified, < 162022-09-20
CVE-2022-32883 [MEDIUM] CWE-284 CVE-2022-32883: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.6,
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to read sensitive location information.
cvelistv5nvd
CVE-2022-32868MEDIUMCVSS 4.3≥ unspecified, < 162022-09-20
CVE-2022-32868 [MEDIUM] CVE-2022-32868: A logic issue was addressed with improved state management. This issue is fixed in Safari 16, iOS 16
A logic issue was addressed with improved state management. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. A website may be able to track users through Safari web extensions.
cvelistv5nvd
CVE-2022-32872LOWCVSS 2.4≥ unspecified, < 162022-09-20
CVE-2022-32872 [LOW] CWE-284 CVE-2022-32872: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, iOS 15.7 and
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, iOS 15.7 and iPadOS 15.7. A person with physical access to an iOS device may be able to access photos from the lock screen.
cvelistv5nvd
CVE-2019-25071HIGHCVSS 8.8v12.4.0v12.4.12022-06-25
CVE-2019-25071 [HIGH] CWE-269 CVE-2019-25071: A vulnerability was found in Apple iPhone up to 12.4.1. It has been declared as critical. Affected b
A vulnerability was found in Apple iPhone up to 12.4.1. It has been declared as critical. Affected by this vulnerability is Siri. Playing an audio or video file might be able to initiate Siri on the same device which makes it possible to execute commands remotely. Exploit details have been disclosed to the public. The existence and implications of thi
cvelistv5nvd
CVE-2019-8703CRITICALCVSS 9.8≥ unspecified, < 132021-12-23
CVE-2019-8703 [CRITICAL] CVE-2019-8703: This issue was addressed with improved entitlements. This issue is fixed in watchOS 6, tvOS 13, macO
This issue was addressed with improved entitlements. This issue is fixed in watchOS 6, tvOS 13, macOS Catalina 10.15, iOS 13. An application may be able to gain elevated privileges.
cvelistv5nvd
CVE-2018-4302HIGHCVSS 7.8≥ unspecified, < 112021-12-23
CVE-2018-4302 [HIGH] CWE-476 CVE-2018-4302: A null pointer dereference was addressed with improved validation. This issue is fixed in macOS High
A null pointer dereference was addressed with improved validation. This issue is fixed in macOS High Sierra 10.13, iCloud for Windows 7.0, watchOS 4, iOS 11, iTunes 12.7 for Windows. Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution.
cvelistv5nvd
CVE-2017-13880HIGHCVSS 7.8≥ unspecified, < 11.22021-12-23
CVE-2017-13880 [HIGH] CVE-2017-13880: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 11
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 11.2, watchOS 4.2. An application may be able to execute arbitrary code with kernel privilege.
cvelistv5nvd
CVE-2019-8702MEDIUMCVSS 5.5≥ unspecified, < 12.42021-12-23
CVE-2019-8702 [MEDIUM] CWE-668 CVE-2019-8702: This issue was addressed with a new entitlement. This issue is fixed in macOS Mojave 10.14.6, Securi
This issue was addressed with a new entitlement. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra, iOS 12.4, tvOS 12.4. A local user may be able to read a persistent account identifier.
cvelistv5nvd
CVE-2017-2375LOWCVSS 3.3≥ unspecified, < 10.22021-12-23
CVE-2017-2375 [LOW] CVE-2017-2375: An issue existed in preventing the uploading of CallKit call history to iCloud. This issue was addre
An issue existed in preventing the uploading of CallKit call history to iCloud. This issue was addressed through improved logic. This issue is fixed in iOS 10.2.1. Updates for CallKit call history are sent to iCloud.
cvelistv5nvd
CVE-2021-30798HIGHCVSS 7.5≥ unspecified, < 14.72021-09-08
CVE-2021-30798 [HIGH] CVE-2021-30798: A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, macOS B
A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6. A malicious application may be able to bypass certain Privacy preferences.
cvelistv5nvd
CVE-2021-30760HIGHCVSS 7.8≥ unspecified, < 14.72021-09-08
CVE-2021-30760 [HIGH] CWE-190 CVE-2021-30760: An integer overflow was addressed through improved input validation. This issue is fixed in iOS 14.7
An integer overflow was addressed through improved input validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-005 Mojave, Security Update 2021-004 Catalina. Processing a maliciously crafted font file may lead to arbitrary code execution.
cvelistv5nvd
CVE-2021-30759HIGHCVSS 7.8≥ unspecified, < 14.72021-09-08
CVE-2021-30759 [HIGH] CWE-787 CVE-2021-30759: A stack overflow was addressed with improved input validation. This issue is fixed in iOS 14.7, macO
A stack overflow was addressed with improved input validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-005 Mojave, Security Update 2021-004 Catalina. Processing a maliciously crafted font file may lead to arbitrary code execution.
cvelistv5nvd
CVE-2021-30774HIGHCVSS 7.8≥ unspecified, < 14.72021-09-08
CVE-2021-30774 [HIGH] CVE-2021-30774: A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur
A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. A malicious application may be able to gain root privileges.
cvelistv5nvd
CVE-2021-30775HIGHCVSS 7.8≥ unspecified, < 14.72021-09-08
CVE-2021-30775 [HIGH] CWE-787 CVE-2021-30775: A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 1
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-004 Catalina. Processing a maliciously crafted audio file may lead to arbitrary code execution.
cvelistv5nvd
CVE-2021-30789HIGHCVSS 7.8≥ unspecified, < 14.72021-09-08
CVE-2021-30789 [HIGH] CWE-125 CVE-2021-30789: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.7,
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-004 Catalina. Processing a maliciously crafted font file may lead to arbitrary code execution.
cvelistv5nvd
CVE-2021-30802HIGHCVSS 8.8≥ unspecified, < 14.72021-09-08
CVE-2021-30802 [HIGH] CWE-416 CVE-2021-30802: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.7, tvOS 14.7. Processing maliciously crafted web content may lead to arbitrary code execution.
cvelistv5nvd
CVE-2021-30788HIGHCVSS 7.1≥ unspecified, < 14.72021-09-08
CVE-2021-30788 [HIGH] CVE-2021-30788: This issue was addressed with improved checks. This issue is fixed in iOS 14.7, macOS Big Sur 11.5,
This issue was addressed with improved checks. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-005 Mojave, Security Update 2021-004 Catalina. Processing a maliciously crafted tiff file may lead to a denial-of-service or potentially disclose memory contents.
cvelistv5nvd
CVE-2021-30781HIGHCVSS 7.8≥ unspecified, < 14.72021-09-08
CVE-2021-30781 [HIGH] CVE-2021-30781: This issue was addressed with improved checks. This issue is fixed in iOS 14.7, macOS Big Sur 11.5,
This issue was addressed with improved checks. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-005 Mojave, Security Update 2021-004 Catalina. A local attacker may be able to cause unexpected application termination or arbitrary code execution.
cvelistv5nvd
CVE-2021-30666HIGHCVSS 8.8KEV≥ unspecified, < 12.52021-09-08
CVE-2021-30666 [HIGH] CWE-119 CVE-2021-30666: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.5
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.5.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
cvelistv5nvd