Apple iOS vulnerabilities
1,765 known vulnerabilities affecting apple/ios.
Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7
Vulnerabilities
Page 3 of 89
CVE-2021-30737P1HIGHCVSS 8.8Exploitedv12.5.42021-06-14
CVE-2021-30737 [HIGH] CVE-2021-30737: iOS 12.5.4
Apple Security Update: About the security content of iOS 12.5.4
Product: iOS
Version: 12.5.4
CVE: CVE-2021-30737
Component: Security
Impact: Processing a maliciously crafted certificate may lead to arbitrary code execution
Description: A memory corruption issue in the ASN.1 decoder was addressed by removing the vulnerable code.
apple
CVE-2019-8771P1MEDIUMCVSS 6.1Exploited≥ unspecified, < 132020-10-27
CVE-2019-8771 [MEDIUM] CWE-1021 CVE-2019-8771: This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 13.
This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 13.0.1, iOS 13. Maliciously crafted web content may violate iframe sandboxing policy.
nvdapple
CVE-2020-9850P1CRITICALCVSS 9.8PoC≥ unspecified, < iOS 13.5 and iPadOS 13.52020-06-09
CVE-2020-9850 [CRITICAL] CVE-2020-9850: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 1
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. A remote attacker may be able to cause arbitrary code execution.
nvd
CVE-2017-2404P2HIGHCVSS 7.5Exploitedv10.32017-03-27
CVE-2017-2404 [HIGH] CVE-2017-2404: iOS 10.3
Apple Security Update: About the security content of iOS 10.3
Product: iOS
Version: 10.3
CVE: CVE-2017-2404
Component: Quick Look
Impact: Tapping a tel link in a PDF document could trigger a call without prompting the user
Description: An issue existed when checking the tel URL before initiating calls. This issue was addressed with the addition of a confirmation prompt.
apple
CVE-2017-9417P1CRITICALCVSS 9.8PoCv10.3.32017-07-19
CVE-2017-9417 [CRITICAL] CVE-2017-9417: iOS 10.3.3
Apple Security Update: About the security content of iOS 10.3.3
Product: iOS
Version: 10.3.3
CVE: CVE-2017-9417
Component: Wi-Fi
Impact: An attacker within range may be able to execute arbitrary code on the Wi-Fi chip
Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2017-5753P2MEDIUMCVSS 5.6PoCv11.2.22018-01-08
CVE-2017-5753 [MEDIUM] CVE-2017-5753: iOS 11.2.2
Apple Security Update: About the security content of iOS 11.2.2
Product: iOS
Version: 11.2.2
CVE: CVE-2017-5753
Component: About Apple security updates
Description: iOS 11.2.2 includes security improvements to Safari and WebKit to mitigate the effects of Spectre (CVE-2017-5753 and CVE-2017-5715).
apple
CVE-2018-4162P2HIGHCVSS 8.8PoCv11.32018-03-29
CVE-2018-4162 [HIGH] CVE-2018-4162: iOS 11.3
Apple Security Update: About the security content of iOS 11.3
Product: iOS
Version: 11.3
CVE: CVE-2018-4162
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2016-0801P2CRITICALCVSS 9.8PoCv9.3
CVE-2016-0801 [CRITICAL] CVE-2016-0801: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2016-0801
Component: CVE-ID
apple
CVE-2018-4416P2HIGHCVSS 8.8PoCv12.12018-10-30
CVE-2018-4416 [HIGH] CVE-2018-4416: iOS 12.1
Apple Security Update: About the security content of iOS 12.1
Product: iOS
Version: 12.1
CVE: CVE-2018-4416
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2017-5715P2MEDIUMCVSS 5.6PoCv11.2.22018-01-08
CVE-2017-5715 [MEDIUM] CVE-2017-5715: iOS 11.2.2
Apple Security Update: About the security content of iOS 11.2.2
Product: iOS
Version: 11.2.2
CVE: CVE-2017-5715
Component: About Apple security updates
Description: iOS 11.2.2 includes security improvements to Safari and WebKit to mitigate the effects of Spectre (CVE-2017-5753 and CVE-2017-5715).
apple
CVE-2019-8660P2CRITICALCVSS 9.8PoC≥ unspecified, < iOS 12.42019-12-18
CVE-2019-8660 [CRITICAL] CWE-787 CVE-2019-8660: A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 1
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
nvdapple
CVE-2019-8647P2CRITICALCVSS 9.8PoC≥ unspecified, < iOS 12.42019-12-18
CVE-2019-8647 [CRITICAL] CWE-416 CVE-2019-8647: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.4, tvOS 12.4, watchOS 5.3. A remote attacker may be able to cause arbitrary code execution.
nvdapple
CVE-2019-8613P2CRITICALCVSS 9.8PoC≥ unspecified, < iOS 12.32019-12-18
CVE-2019-8613 [CRITICAL] CWE-416 CVE-2019-8613: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, tvOS 12.3, watchOS 5.2.1. A remote attacker may be able to cause arbitrary code execution.
nvdapple
CVE-2019-8689P2HIGHCVSS 8.8PoC≥ unspecified, < iOS 12.42019-12-18
CVE-2019-8689 [HIGH] CWE-787 CVE-2019-8689: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2019-8672P2HIGHCVSS 8.8PoC≥ unspecified, < iOS 12.42019-12-18
CVE-2019-8672 [HIGH] CWE-787 CVE-2019-8672: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2019-8820P2HIGHCVSS 8.8PoC≥ unspecified, < iOS 13.2 and iPadOS 13.22019-12-18
CVE-2019-8820 [HIGH] CWE-787 CVE-2019-8820: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8641P2CRITICALCVSS 9.8PoC≥ unspecified, < iOS 12.4.2≥ unspecified, < iOS 132019-12-18
CVE-2019-8641 [CRITICAL] CWE-125 CVE-2019-8641: An out-of-bounds read was addressed with improved input validation.
An out-of-bounds read was addressed with improved input validation.
nvdapple
CVE-2018-4222P2HIGHCVSS 8.8PoCv11.42018-05-29
CVE-2018-4222 [HIGH] CVE-2018-4222: iOS 11.4
Apple Security Update: About the security content of iOS 11.4
Product: iOS
Version: 11.4
CVE: CVE-2018-4222
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: An out-of-bounds read was addressed with improved input validation.
apple
CVE-2019-6215P2HIGHCVSS 8.8PoC≥ unspecified, < iOS 12.1.32019-03-05
CVE-2019-6215 [HIGH] CWE-843 CVE-2019-6215: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2017-2547P2HIGHCVSS 8.8PoCv10.3.22017-05-15
CVE-2017-2547 [HIGH] CVE-2017-2547: iOS 10.3.2
Apple Security Update: About the security content of iOS 10.3.2
Product: iOS
Version: 10.3.2
CVE: CVE-2017-2547
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
apple