Apple iOS vulnerabilities
479 known vulnerabilities affecting apple/ios.
Total CVEs
479
CISA KEV
18
actively exploited
Public exploits
36
Exploited in wild
19
Severity breakdown
CRITICAL32HIGH288MEDIUM132LOW27
Vulnerabilities
Page 3 of 24
CVE-2021-30797HIGHCVSS 8.8≥ unspecified, < 14.72021-09-08
CVE-2021-30797 [HIGH] CVE-2021-30797: This issue was addressed with improved checks. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS
This issue was addressed with improved checks. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing maliciously crafted web content may lead to code execution.
cvelistv5nvd
CVE-2021-30780HIGHCVSS 7.8≥ unspecified, < 14.72021-09-08
CVE-2021-30780 [HIGH] CWE-787 CVE-2021-30780: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-005 Mojave, Security Update 2021-004 Catalina. A malicious application may be able to gain root privileges.
cvelistv5nvd
CVE-2021-30762HIGHCVSS 8.8KEV≥ unspecified, < 12.52021-09-08
CVE-2021-30762 [HIGH] CWE-416 CVE-2021-30762: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
cvelistv5nvd
CVE-2021-30795HIGHCVSS 8.8≥ unspecified, < 14.72021-09-08
CVE-2021-30795 [HIGH] CWE-416 CVE-2021-30795: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing maliciously crafted web content may lead to arbitrary code execution.
cvelistv5nvd
CVE-2021-30792HIGHCVSS 7.8≥ unspecified, < 14.72021-09-08
CVE-2021-30792 [HIGH] CWE-787 CVE-2021-30792: An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.7
An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5. Processing a maliciously crafted image may lead to arbitrary code execution.
cvelistv5nvd
CVE-2021-30779HIGHCVSS 7.8≥ unspecified, < 14.72021-09-08
CVE-2021-30779 [HIGH] CVE-2021-30779: This issue was addressed with improved checks. This issue is fixed in iOS 14.7, macOS Big Sur 11.5,
This issue was addressed with improved checks. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing a maliciously crafted image may lead to arbitrary code execution.
cvelistv5nvd
CVE-2021-30786HIGHCVSS 7.0≥ unspecified, < 14.72021-09-08
CVE-2021-30786 [HIGH] CWE-362 CVE-2021-30786: A race condition was addressed with improved state handling. This issue is fixed in iOS 14.7, macOS
A race condition was addressed with improved state handling. This issue is fixed in iOS 14.7, macOS Big Sur 11.5. Opening a maliciously crafted PDF file may lead to an unexpected application termination or arbitrary code execution.
cvelistv5nvd
CVE-2021-30748HIGHCVSS 7.8≥ unspecified, < 14.72021-09-08
CVE-2021-30748 [HIGH] CWE-787 CVE-2021-30748: A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 1
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 14.7, macOS Big Sur 11.5. An application may be able to execute arbitrary code with kernel privileges.
cvelistv5nvd
CVE-2021-30785HIGHCVSS 7.8≥ unspecified, < 14.72021-09-08
CVE-2021-30785 [HIGH] CWE-120 CVE-2021-30785: A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 14.7, macO
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-004 Catalina. Processing a maliciously crafted image may lead to arbitrary code execution.
cvelistv5nvd
CVE-2021-30761HIGHCVSS 8.8KEV≥ unspecified, < 12.52021-09-08
CVE-2021-30761 [HIGH] CWE-787 CVE-2021-30761: A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 1
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
cvelistv5nvd
CVE-2021-30799HIGHCVSS 8.8≥ unspecified, < 14.72021-09-08
CVE-2021-30799 [HIGH] CWE-787 CVE-2021-30799: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. Processing maliciously crafted web content may lead to arbitrary code execution.
cvelistv5nvd
CVE-2021-30758HIGHCVSS 8.8≥ unspecified, < 14.72021-09-08
CVE-2021-30758 [HIGH] CWE-843 CVE-2021-30758: A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.7,
A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing maliciously crafted web content may lead to arbitrary code execution.
cvelistv5nvd
CVE-2021-30800HIGHCVSS 8.8≥ unspecified, < 14.72021-09-08
CVE-2021-30800 [HIGH] CVE-2021-30800: This issue was addressed with improved checks. This issue is fixed in iOS 14.7. Joining a malicious
This issue was addressed with improved checks. This issue is fixed in iOS 14.7. Joining a malicious Wi-Fi network may result in a denial of service or arbitrary code execution.
cvelistv5nvd
CVE-2021-30791MEDIUMCVSS 5.5≥ unspecified, < 14.72021-09-08
CVE-2021-30791 [MEDIUM] CWE-125 CVE-2021-30791: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 14.7,
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 14.7, macOS Big Sur 11.5. Processing a maliciously crafted file may disclose user information.
cvelistv5nvd
CVE-2021-30770MEDIUMCVSS 5.5≥ unspecified, < 14.72021-09-08
CVE-2021-30770 [MEDIUM] CWE-287 CVE-2021-30770: A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, tvOS 14.7, wa
A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. An attacker that has already achieved kernel code execution may be able to bypass kernel memory mitigations.
cvelistv5nvd
CVE-2021-30773MEDIUMCVSS 5.5≥ unspecified, < 14.72021-09-08
CVE-2021-30773 [MEDIUM] CVE-2021-30773: An issue in code signature validation was addressed with improved checks. This issue is fixed in iOS
An issue in code signature validation was addressed with improved checks. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A malicious application may be able to bypass code signing checks.
cvelistv5nvd
CVE-2021-30796MEDIUMCVSS 6.5≥ unspecified, < 14.72021-09-08
CVE-2021-30796 [MEDIUM] CVE-2021-30796: A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur
A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. Processing a maliciously crafted image may lead to a denial of service.
cvelistv5nvd
CVE-2021-30776MEDIUMCVSS 5.5≥ unspecified, < 14.72021-09-08
CVE-2021-30776 [MEDIUM] CVE-2021-30776: A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur
A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-004 Catalina. Playing a malicious audio file may lead to an unexpected application termination.
cvelistv5nvd
CVE-2021-30768MEDIUMCVSS 5.5≥ unspecified, < 14.72021-09-08
CVE-2021-30768 [MEDIUM] CVE-2021-30768: A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur
A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-004 Catalina. A sandboxed process may be able to circumvent sandbox restrictions.
cvelistv5nvd
CVE-2021-30769MEDIUMCVSS 5.5≥ unspecified, < 14.72021-09-08
CVE-2021-30769 [MEDIUM] CWE-287 CVE-2021-30769: A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, tvOS 14
A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
cvelistv5nvd