Apple iOS vulnerabilities
1,765 known vulnerabilities affecting apple/ios.
Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7
Vulnerabilities
Page 34 of 89
CVE-2019-8779P3CRITICALCVSS 10.0≥ unspecified, < iOS 13.1.1 and iPadOS 13.1.12019-12-18
CVE-2019-8779 [CRITICAL] CWE-668 CVE-2019-8779: A logic issue applied the incorrect restrictions. This issue was addressed by updating the logic to
A logic issue applied the incorrect restrictions. This issue was addressed by updating the logic to apply the correct restrictions. This issue is fixed in iOS 13.1.1 and iPadOS 13.1.1. Third party app extensions may not receive the correct sandbox restrictions.
nvd
CVE-2020-9898P3CRITICALCVSS 9.8≥ unspecified, < iOS 13.6 and iPadOS 13.62020-10-22
CVE-2020-9898 [CRITICAL] CVE-2020-9898: This issue was addressed with improved entitlements. This issue is fixed in iOS 13.6 and iPadOS 13.6
This issue was addressed with improved entitlements. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2015-6986P3CRITICALCVSS 9.3v9.1
CVE-2015-6986 [CRITICAL] CVE-2015-6986: iOS 9.1
Apple Security Update: About the security content of iOS 9.1
Product: iOS
Version: 9.1
CVE: CVE-2015-6986
Component: CVE-ID
apple
CVE-2018-20505P3HIGHCVSS 7.5v12.1.32019-01-22
CVE-2018-20505 [HIGH] CVE-2018-20505: iOS 12.1.3
Apple Security Update: About the security content of iOS 12.1.3
Product: iOS
Version: 12.1.3
CVE: CVE-2018-20505
Component: SQLite
Impact: A maliciously crafted SQL query may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved input validation.
apple
CVE-2015-1100P4MEDIUMCVSS 5.4PoCv8.3
CVE-2015-1100 [MEDIUM] CVE-2015-1100: iOS 8.3
Apple Security Update: About the security content of iOS 8.3
Product: iOS
Version: 8.3
CVE: CVE-2015-1100
Component: CVE-ID
apple
CVE-2016-9843P3CRITICALCVSS 9.8v112017-09-19
CVE-2016-9843 [CRITICAL] CVE-2016-9843: iOS 11
Apple Security Update: About the security content of iOS 11
Product: iOS
Version: 11
CVE: CVE-2016-9843
Component: CVE-2016-9843
apple
CVE-2018-4214P3HIGHCVSS 8.8v11.42018-05-29
CVE-2018-4214 [HIGH] CVE-2018-4214: iOS 11.4
Apple Security Update: About the security content of iOS 11.4
Product: iOS
Version: 11.4
CVE: CVE-2018-4214
Component: WebKit
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: A memory corruption issue was addressed with improved input validation.
apple
CVE-2018-4208P3HIGHCVSS 8.8v11.32018-03-29
CVE-2018-4208 [HIGH] CVE-2018-4208: iOS 11.3
Apple Security Update: About the security content of iOS 11.3
Product: iOS
Version: 11.3
CVE: CVE-2018-4208
Component: WebKit
Impact: Unexpected interaction causes an ASSERT failure
Description: This issue was addressed with improved checks.
apple
CVE-2018-4209P3HIGHCVSS 8.8v11.32018-03-29
CVE-2018-4209 [HIGH] CVE-2018-4209: iOS 11.3
Apple Security Update: About the security content of iOS 11.3
Product: iOS
Version: 11.3
CVE: CVE-2018-4209
Component: WebKit
Impact: Unexpected interaction causes an ASSERT failure
Description: This issue was addressed with improved checks.
apple
CVE-2018-4212P3HIGHCVSS 8.8v11.32018-03-29
CVE-2018-4212 [HIGH] CVE-2018-4212: iOS 11.3
Apple Security Update: About the security content of iOS 11.3
Product: iOS
Version: 11.3
CVE: CVE-2018-4212
Component: WebKit
Impact: Unexpected interaction causes an ASSERT failure
Description: This issue was addressed with improved checks.
apple
CVE-2018-4207P3HIGHCVSS 8.8v11.32018-03-29
CVE-2018-4207 [HIGH] CVE-2018-4207: iOS 11.3
Apple Security Update: About the security content of iOS 11.3
Product: iOS
Version: 11.3
CVE: CVE-2018-4207
Component: WebKit
Impact: Unexpected interaction causes an ASSERT failure
Description: This issue was addressed with improved checks.
apple
CVE-2018-4213P3HIGHCVSS 8.8v11.32018-03-29
CVE-2018-4213 [HIGH] CVE-2018-4213: iOS 11.3
Apple Security Update: About the security content of iOS 11.3
Product: iOS
Version: 11.3
CVE: CVE-2018-4213
Component: WebKit
Impact: Unexpected interaction causes an ASSERT failure
Description: This issue was addressed with improved checks.
apple
CVE-2018-4149P3HIGHCVSS 8.8v11.32018-03-29
CVE-2018-4149 [HIGH] CVE-2018-4149: iOS 11.3
Apple Security Update: About the security content of iOS 11.3
Product: iOS
Version: 11.3
CVE: CVE-2018-4149
Component: SafariViewController
Impact: Visiting a malicious website may lead to user interface spoofing
Description: A state management issue was addressed by disabling text input until the destination page loads.
apple
CVE-2018-4134P3HIGHCVSS 8.8v11.32018-03-29
CVE-2018-4134 [HIGH] CVE-2018-4134: iOS 11.3
Apple Security Update: About the security content of iOS 11.3
Product: iOS
Version: 11.3
CVE: CVE-2018-4134
Component: Safari
Impact: Visiting a malicious website by clicking a link may lead to user interface spoofing
Description: An inconsistent user interface issue was addressed with improved state management.
apple
CVE-2018-4437P3HIGHCVSS 8.8v12.1.12018-12-05
CVE-2018-4437 [HIGH] CVE-2018-4437: iOS 12.1.1
Apple Security Update: About the security content of iOS 12.1.1
Product: iOS
Version: 12.1.1
CVE: CVE-2018-4437
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2018-4464P3HIGHCVSS 8.8v12.1.12018-12-05
CVE-2018-4464 [HIGH] CVE-2018-4464: iOS 12.1.1
Apple Security Update: About the security content of iOS 12.1.1
Product: iOS
Version: 12.1.1
CVE: CVE-2018-4464
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2018-4392P3HIGHCVSS 8.8v12.12018-10-30
CVE-2018-4392 [HIGH] CVE-2018-4392: iOS 12.1
Apple Security Update: About the security content of iOS 12.1
Product: iOS
Version: 12.1
CVE: CVE-2018-4392
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2016-4591P3HIGHCVSS 7.5v9.3.32016-07-18
CVE-2016-4591 [HIGH] CVE-2016-4591: iOS 9.3.3
Apple Security Update: About the security content of iOS 9.3.3
Product: iOS
Version: 9.3.3
CVE: CVE-2016-4591
Component: WebKit
Impact: Visiting a maliciously crafted website may leak sensitive data
Description: A permissions issue existed in the handling of the location variable. This was addressed though additional ownership checks.
apple
CVE-2014-4485P3HIGHCVSS 7.5v8.1.3
CVE-2014-4485 [HIGH] CVE-2014-4485: iOS 8.1.3
Apple Security Update: About the security content of iOS 8.1.3
Product: iOS
Version: 8.1.3
CVE: CVE-2014-4485
Component: CVE-ID
apple
CVE-2020-9865P3HIGHCVSS 8.6≥ unspecified, < iOS 13.6 and iPadOS 13.62020-10-16
CVE-2020-9865 [HIGH] CWE-787 CVE-2020-9865: A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS
A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A malicious application may be able to break out of its sandbox.
nvd