Apple iOS vulnerabilities
1,765 known vulnerabilities affecting apple/ios.
Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7
Vulnerabilities
Page 32 of 89
CVE-2018-4249P3HIGHCVSS 7.8v11.42018-05-29
CVE-2018-4249 [HIGH] CVE-2018-4249: iOS 11.4
Apple Security Update: About the security content of iOS 11.4
Product: iOS
Version: 11.4
CVE: CVE-2018-4249
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2020-9876P3HIGHCVSS 7.8≥ unspecified, < iOS 13.6 and iPadOS 13.62020-10-22
CVE-2020-9876 [HIGH] CWE-787 CVE-2020-9876: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Opening a maliciously crafted PDF file may lead to an unexpected application termination or arbitrary
nvd
CVE-2020-9889P3HIGHCVSS 7.8≥ unspecified, < iOS 13.6 and iPadOS 13.62020-10-16
CVE-2020-9889 [HIGH] CWE-787 CVE-2020-9889: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. Processing a maliciously crafted audio file may lead to arbitrary code execution.
nvd
CVE-2016-9842P3HIGHCVSS 8.8v112017-09-19
CVE-2016-9842 [HIGH] CVE-2016-9842: iOS 11
Apple Security Update: About the security content of iOS 11
Product: iOS
Version: 11
CVE: CVE-2016-9842
Component: CVE-2016-9842
apple
CVE-2016-1835P3HIGHCVSS 8.8v9.3.2
CVE-2016-1835 [HIGH] CVE-2016-1835: iOS 9.3.2
Apple Security Update: About the security content of iOS 9.3.2
Product: iOS
Version: 9.3.2
CVE: CVE-2016-1835
Component: CVE-ID
Impact: Visiting a maliciously crafted website may lead to arbitrary code execution
Description: A memory corruption issue was addressed through improved memory handling.
apple
CVE-2015-7006P3MEDIUMCVSS 6.8v9.1
CVE-2015-7006 [MEDIUM] CVE-2015-7006: iOS 9.1
Apple Security Update: About the security content of iOS 9.1
Product: iOS
Version: 9.1
CVE: CVE-2015-7006
Component: CVE-ID
apple
CVE-2020-9919P3HIGHCVSS 7.8≥ unspecified, < iOS 13.6 and iPadOS 13.62020-10-22
CVE-2020-9919 [HIGH] CWE-787 CVE-2020-9919: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2018-4115P3CRITICALCVSS 9.8v11.32018-03-29
CVE-2018-4115 [CRITICAL] CVE-2018-4115: iOS 11.3
Apple Security Update: About the security content of iOS 11.3
Product: iOS
Version: 11.3
CVE: CVE-2018-4115
Component: System Preferences
Impact: A configuration profile may incorrectly remain in effect after removal
Description: An issue existed in CFPreferences. This issue was addressed with improved preferences cleanup.
apple
CVE-2016-9840P3HIGHCVSS 8.8v112017-09-19
CVE-2016-9840 [HIGH] CVE-2016-9840: iOS 11
Apple Security Update: About the security content of iOS 11
Product: iOS
Version: 11
CVE: CVE-2016-9840
Component: CVE-2016-9840
apple
CVE-2021-30792P3HIGHCVSS 7.8≥ unspecified, < 14.72021-09-08
CVE-2021-30792 [HIGH] CWE-787 CVE-2021-30792: An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.7
An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2015-7111P3CRITICALCVSS 9.3v9.2
CVE-2015-7111 [CRITICAL] CVE-2015-7111: iOS 9.2
Apple Security Update: About the security content of iOS 9.2
Product: iOS
Version: 9.2
CVE: CVE-2015-7111
Component: CVE-ID
apple
CVE-2018-4189P3CRITICALCVSS 9.8v11.2.52018-01-23
CVE-2018-4189 [CRITICAL] CVE-2018-4189: iOS 11.2.5
Apple Security Update: About the security content of iOS 11.2.5
Product: iOS
Version: 11.2.5
CVE: CVE-2018-4189
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2019-6206P3CRITICALCVSS 9.8≥ unspecified, < iOS 12.1.32019-03-04
CVE-2019-6206 [CRITICAL] CWE-200 CVE-2019-6206: An issue existed with autofill resuming after it was canceled. The issue was addressed with improved
An issue existed with autofill resuming after it was canceled. The issue was addressed with improved state management. This issue is fixed in iOS 12.1.3. Password autofill may fill in passwords after they were manually cleared.
nvdapple
CVE-2022-32911P3HIGHCVSS 7.8≥ unspecified, < 162022-09-20
CVE-2022-32911 [HIGH] CWE-787 CVE-2022-32911: The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6, i
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2015-7069P3CRITICALCVSS 9.3v9.2
CVE-2015-7069 [CRITICAL] CVE-2015-7069: iOS 9.2
Apple Security Update: About the security content of iOS 9.2
Product: iOS
Version: 9.2
CVE: CVE-2015-7069
Component: CVE-ID
Impact: Parsing a maliciously crafted iBooks file may lead to disclosure of user information
Description: An XML external entity reference issue existed with iBook parsing. This issue was addressed through improved parsing.
apple
CVE-2015-7070P3CRITICALCVSS 9.3v9.2
CVE-2015-7070 [CRITICAL] CVE-2015-7070: iOS 9.2
Apple Security Update: About the security content of iOS 9.2
Product: iOS
Version: 9.2
CVE: CVE-2015-7070
Component: CVE-ID
Impact: Parsing a maliciously crafted iBooks file may lead to disclosure of user information
Description: An XML external entity reference issue existed with iBook parsing. This issue was addressed through improved parsing.
apple
CVE-2019-8531P3CRITICALCVSS 9.8≥ unspecified, < 12.22020-10-27
CVE-2019-8531 [CRITICAL] CWE-295 CVE-2019-8531: A validation issue existed in Trust Anchor Management. This issue was addressed with improved valida
A validation issue existed in Trust Anchor Management. This issue was addressed with improved validation. This issue is fixed in watchOS 5.2, macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, iOS 12.2. An untrusted radius server certificate may be trusted.
nvdapple
CVE-2016-4729P3HIGHCVSS 8.8v102016-09-13
CVE-2016-4729 [HIGH] CVE-2016-4729: iOS 10
Apple Security Update: About the security content of iOS 10
Product: iOS
Version: 10
CVE: CVE-2016-4729
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed through improved memory handling.
apple
CVE-2016-4731P3HIGHCVSS 8.8v102016-09-13
CVE-2016-4731 [HIGH] CVE-2016-4731: iOS 10
Apple Security Update: About the security content of iOS 10
Product: iOS
Version: 10
CVE: CVE-2016-4731
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed through improved memory handling.
apple
CVE-2018-4262P3HIGHCVSS 8.8v11.4.12018-07-09
CVE-2018-4262 [HIGH] CVE-2018-4262: iOS 11.4.1
Apple Security Update: About the security content of iOS 11.4.1
Product: iOS
Version: 11.4.1
CVE: CVE-2018-4262
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
apple