Apple iOS vulnerabilities
1,765 known vulnerabilities affecting apple/ios.
Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7
Vulnerabilities
Page 31 of 89
CVE-2018-4272P3HIGHCVSS 8.8v11.4.12018-07-09
CVE-2018-4272 [HIGH] CVE-2018-4272: iOS 11.4.1
Apple Security Update: About the security content of iOS 11.4.1
Product: iOS
Version: 11.4.1
CVE: CVE-2018-4272
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2018-4264P3HIGHCVSS 8.8v11.4.12018-07-09
CVE-2018-4264 [HIGH] CVE-2018-4264: iOS 11.4.1
Apple Security Update: About the security content of iOS 11.4.1
Product: iOS
Version: 11.4.1
CVE: CVE-2018-4264
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2016-1847P3HIGHCVSS 8.8v9.3.2
CVE-2016-1847 [HIGH] CVE-2016-1847: iOS 9.3.2
Apple Security Update: About the security content of iOS 9.3.2
Product: iOS
Version: 9.3.2
CVE: CVE-2016-1847
Component: CVE-ID
apple
CVE-2017-6983P3HIGHCVSS 8.8v10.3.22017-05-15
CVE-2017-6983 [HIGH] CVE-2017-6983: iOS 10.3.2
Apple Security Update: About the security content of iOS 10.3.2
Product: iOS
Version: 10.3.2
CVE: CVE-2017-6983
Component: SQLite
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved input validation.
apple
CVE-2018-4194P3HIGHCVSS 8.8v11.42018-05-29
CVE-2018-4194 [HIGH] CVE-2018-4194: iOS 11.4
Apple Security Update: About the security content of iOS 11.4
Product: iOS
Version: 11.4
CVE: CVE-2018-4194
Component: CoreGraphics
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: An out-of-bounds read was addressed with improved input validation.
apple
CVE-2016-4584P3HIGHCVSS 8.8v9.3.32016-07-18
CVE-2016-4584 [HIGH] CVE-2016-4584: iOS 9.3.3
Apple Security Update: About the security content of iOS 9.3.3
Product: iOS
Version: 9.3.3
CVE: CVE-2016-4584
Component: WebKit Page Loading
Impact: Visiting a maliciously crafted website may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed through improved memory handling.
apple
CVE-2017-7002P3HIGHCVSS 8.8v10.3.22017-05-15
CVE-2017-7002 [HIGH] CVE-2017-7002: iOS 10.3.2
Apple Security Update: About the security content of iOS 10.3.2
Product: iOS
Version: 10.3.2
CVE: CVE-2017-7002
Component: SQLite
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved input validation.
apple
CVE-2018-4372P3HIGHCVSS 8.8v12.12018-10-30
CVE-2018-4372 [HIGH] CVE-2018-4372: iOS 12.1
Apple Security Update: About the security content of iOS 12.1
Product: iOS
Version: 12.1
CVE: CVE-2018-4372
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2017-6991P3HIGHCVSS 8.8v10.3.22017-05-15
CVE-2017-6991 [HIGH] CVE-2017-6991: iOS 10.3.2
Apple Security Update: About the security content of iOS 10.3.2
Product: iOS
Version: 10.3.2
CVE: CVE-2017-6991
Component: SQLite
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved input validation.
apple
CVE-2015-6983P3HIGHCVSS 8.8v9.1
CVE-2015-6983 [HIGH] CVE-2015-6983: iOS 9.1
Apple Security Update: About the security content of iOS 9.1
Product: iOS
Version: 9.1
CVE: CVE-2015-6983
Component: CVE-ID
apple
CVE-2016-7594P3HIGHCVSS 8.8v10.22016-12-12
CVE-2016-7594 [HIGH] CVE-2016-7594: iOS 10.2
Apple Security Update: About the security content of iOS 10.2
Product: iOS
Version: 10.2
CVE: CVE-2016-7594
Component: ICU
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: A memory corruption issue was addressed through improved memory handling.
apple
CVE-2016-4611P3HIGHCVSS 8.8v102016-09-13
CVE-2016-4611 [HIGH] CVE-2016-4611: iOS 10
Apple Security Update: About the security content of iOS 10
Product: iOS
Version: 10
CVE: CVE-2016-4611
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed through improved memory handling.
apple
CVE-2017-2506P3HIGHCVSS 8.8v10.3.22017-05-15
CVE-2017-2506 [HIGH] CVE-2017-2506: iOS 10.3.2
Apple Security Update: About the security content of iOS 10.3.2
Product: iOS
Version: 10.3.2
CVE: CVE-2017-2506
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2018-4378P3HIGHCVSS 8.8v12.12018-10-30
CVE-2018-4378 [HIGH] CVE-2018-4378: iOS 12.1
Apple Security Update: About the security content of iOS 12.1
Product: iOS
Version: 12.1
CVE: CVE-2018-4378
Component: WebKit
Impact: Processing maliciously crafted web content may lead to code execution
Description: A memory corruption issue was addressed with improved validation.
apple
CVE-2020-9992P3HIGHCVSS 7.8≥ unspecified, < iOS 14.0 and iPadOS 14.02020-10-16
CVE-2020-9992 [HIGH] CVE-2020-9992: This issue was addressed by encrypting communications over the network to devices running iOS 14, iP
This issue was addressed by encrypting communications over the network to devices running iOS 14, iPadOS 14, tvOS 14, and watchOS 7. This issue is fixed in iOS 14.0 and iPadOS 14.0, Xcode 12.0. An attacker in a privileged network position may be able to execute arbitrary code on a paired device during a debug session over the network.
nvd
CVE-2014-4489P3CRITICALCVSS 10.0v8.1.3
CVE-2014-4489 [CRITICAL] CVE-2014-4489: iOS 8.1.3
Apple Security Update: About the security content of iOS 8.1.3
Product: iOS
Version: 8.1.3
CVE: CVE-2014-4489
Component: CVE-ID
Impact: A website may be able to bypass sandbox restrictions using the iTunes Store
Description: An issue existed in the handling of URLs redirected from Safari to the iTunes Store that could allow a malicious website to bypass Safari's sandbox restrictions. The issue was addressed with improved filtering of URLs opened
apple
CVE-2014-4486P3CRITICALCVSS 10.0v8.1.3
CVE-2014-4486 [CRITICAL] CVE-2014-4486: iOS 8.1.3
Apple Security Update: About the security content of iOS 8.1.3
Product: iOS
Version: 8.1.3
CVE: CVE-2014-4486
Component: CVE-ID
apple
CVE-2022-32892P3HIGHCVSS 8.6v162022-09-12
CVE-2022-32892 [HIGH] CVE-2022-32892: iOS 16
Apple Security Update: About the security content of iOS 16
Product: iOS
Version: 16
CVE: CVE-2022-32892
Component: WebKit Sandboxing
Impact: A sandboxed process may be able to circumvent sandbox restrictions
Description: An access issue was addressed with improvements to the sandbox.
apple
CVE-2015-7113P3CRITICALCVSS 10.0v9.2
CVE-2015-7113 [CRITICAL] CVE-2015-7113: iOS 9.2
Apple Security Update: About the security content of iOS 9.2
Product: iOS
Version: 9.2
CVE: CVE-2015-7113
Component: CVE-ID
Impact: Visiting a maliciously crafted website may lead to arbitrary code execution
Description: A memory corruption issue existed in the processing of archives. This issue was addressed through improved memory handling.
apple
CVE-2014-4480P3CRITICALCVSS 10.0v8.1.3
CVE-2014-4480 [CRITICAL] CVE-2014-4480: iOS 8.1.3
Apple Security Update: About the security content of iOS 8.1.3
Product: iOS
Version: 8.1.3
CVE: CVE-2014-4480
Component: CVE-ID
apple