Apple iOS vulnerabilities
1,765 known vulnerabilities affecting apple/ios.
Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7
Vulnerabilities
Page 71 of 89
CVE-2022-32891P4MEDIUMCVSS 6.1≥ unspecified, < 162023-02-27
CVE-2022-32891 [MEDIUM] CWE-1021 CVE-2022-32891: The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchO
The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchOS 9, iOS 16. Visiting a website that frames malicious content may lead to UI spoofing.
nvdapple
CVE-2017-2411P4MEDIUMCVSS 5.9v11.22017-12-02
CVE-2017-2411 [MEDIUM] CVE-2017-2411: iOS 11.2
Apple Security Update: About the security content of iOS 11.2
Product: iOS
Version: 11.2
CVE: CVE-2017-2411
Component: Calculator
Impact: An attacker with a privileged network position may be able to alter currency conversion rates
Description: Exchange rates were retrieved from HTTP rather than HTTPS. This was addressed by enabling HTTPS for exchange rates.
apple
CVE-2019-8540P4MEDIUMCVSS 5.5≥ unspecified, < iOS 12.22019-12-18
CVE-2019-8540 [MEDIUM] CWE-665 CVE-2019-8540: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iO
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to determine kernel memory layout.
nvdapple
CVE-2015-3752P4MEDIUMCVSS 5.0v8.4.1
CVE-2015-3752 [MEDIUM] CVE-2015-3752: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-3752
Component: CVE-ID
apple
CVE-2017-13804P4MEDIUMCVSS 5.5v11.12017-10-31
CVE-2017-13804 [MEDIUM] CVE-2017-13804: iOS 11.1
Apple Security Update: About the security content of iOS 11.1
Product: iOS
Version: 11.1
CVE: CVE-2017-13804
Component: StreamingZip
Impact: A malicious zip file may be able modify restricted areas of the file system
Description: A path handling issue was addressed with improved validation.
apple
CVE-2016-4590P4MEDIUMCVSS 5.4v9.3.32016-07-18
CVE-2016-4590 [MEDIUM] CVE-2016-4590: iOS 9.3.3
Apple Security Update: About the security content of iOS 9.3.3
Product: iOS
Version: 9.3.3
CVE: CVE-2016-4590
Component: WebKit
Impact: Visiting a malicious website may lead to user interface spoofing
Description: An origin inheritance issue existed in parsing of about: URLs. This was addressed through improved validation of security origins.
apple
CVE-2021-30773P4MEDIUMCVSS 5.5≥ unspecified, < 14.72021-09-08
CVE-2021-30773 [MEDIUM] CVE-2021-30773: An issue in code signature validation was addressed with improved checks. This issue is fixed in iOS
An issue in code signature validation was addressed with improved checks. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A malicious application may be able to bypass code signing checks.
nvd
CVE-2017-2400P4MEDIUMCVSS 5.3v10.32017-03-27
CVE-2017-2400 [MEDIUM] CVE-2017-2400: iOS 10.3
Apple Security Update: About the security content of iOS 10.3
Product: iOS
Version: 10.3
CVE: CVE-2017-2400
Component: SafariViewController
Impact: Cache state is not properly kept in sync between Safari and SafariViewController when a user clears Safari cache
Description: An issue existed in clearing Safari cache information from SafariViewController. This issue was addressed by improving cache state handling.
apple
CVE-2014-4496P4MEDIUMCVSS 5.0v8.1.3
CVE-2014-4496 [MEDIUM] CVE-2014-4496: iOS 8.1.3
Apple Security Update: About the security content of iOS 8.1.3
Product: iOS
Version: 8.1.3
CVE: CVE-2014-4496
Component: CVE-ID
Impact: A malicious, sandboxed app can compromise the networkd daemon
Description: Multiple type confusion issues existed in networkd's handling of interprocess communication. By sending a maliciously formatted message to networkd, it may have been possible to execute arbitrary code as the networkd process. The issue is ad
apple
CVE-2015-1089P4MEDIUMCVSS 5.0v8.3
CVE-2015-1089 [MEDIUM] CVE-2015-1089: iOS 8.3
Apple Security Update: About the security content of iOS 8.3
Product: iOS
Version: 8.3
CVE: CVE-2015-1089
Component: CVE-ID
apple
CVE-2022-32883P4MEDIUMCVSS 5.5≥ unspecified, < 162022-09-20
CVE-2022-32883 [MEDIUM] CWE-284 CVE-2022-32883: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.6,
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to read sensitive location information.
nvdapple
CVE-2019-8796P4MEDIUMCVSS 5.3v12.4.32019-10-28
CVE-2019-8796 [MEDIUM] CVE-2019-8796: iOS 12.4.3
Apple Security Update: About the security content of iOS 12.4.3
Product: iOS
Version: 12.4.3
CVE: CVE-2019-8796
Component: Accounts
Impact: AirDrop transfers may be unexpectedly accepted while in Everyone mode
Description: A logic issue was addressed with improved validation.
apple
CVE-2017-7078P4MEDIUMCVSS 5.3v112017-09-19
CVE-2017-7078 [MEDIUM] CVE-2017-7078: iOS 11
Apple Security Update: About the security content of iOS 11
Product: iOS
Version: 11
CVE: CVE-2017-7078
Component: Mail Drafts
Impact: An attacker with a privileged network position may be able to intercept mail contents
Description: An encryption issue existed in the handling of mail drafts. This issue was addressed with improved handling of mail drafts meant to be sent encrypted.
apple
CVE-2021-30770P4MEDIUMCVSS 5.5≥ unspecified, < 14.72021-09-08
CVE-2021-30770 [MEDIUM] CWE-287 CVE-2021-30770: A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, tvOS 14.7, wa
A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. An attacker that has already achieved kernel code execution may be able to bypass kernel memory mitigations.
nvd
CVE-2017-2390P4MEDIUMCVSS 5.5v10.32017-03-27
CVE-2017-2390 [MEDIUM] CVE-2017-2390: iOS 10.3
Apple Security Update: About the security content of iOS 10.3
Product: iOS
Version: 10.3
CVE: CVE-2017-2390
Component: Keychain
Impact: An attacker who is able to intercept TLS connections may be able to read secrets protected by iCloud Keychain.
Description: In certain circumstances, iCloud Keychain failed to validate the authenticity of OTR packets. This issue was addressed through improved validation.
apple
CVE-2017-7146P4MEDIUMCVSS 5.3v112017-09-19
CVE-2017-7146 [MEDIUM] CVE-2017-7146: iOS 11
Apple Security Update: About the security content of iOS 11
Product: iOS
Version: 11
CVE: CVE-2017-7146
Component: Security
Impact: A malicious app may be able to track users between installs
Description: A permission checking issue existed in the handling of an app's Keychain data. This issue was addressed with improved permission checking.
apple
CVE-2016-7619P4MEDIUMCVSS 5.5v10.22016-12-12
CVE-2016-7619 [MEDIUM] CVE-2016-7619: iOS 10.2
Apple Security Update: About the security content of iOS 10.2
Product: iOS
Version: 10.2
CVE: CVE-2016-7619
Component: Kernel
Impact: A malicious application may gain access to a device's MAC address
Description: An access issue was addressed through additional sandbox restrictions on third party applications.
apple
CVE-2022-32864P4MEDIUMCVSS 5.5≥ unspecified, < 162022-09-20
CVE-2022-32864 [MEDIUM] CVE-2022-32864: The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6, i
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to disclose kernel memory.
nvdapple
CVE-2017-7145P4MEDIUMCVSS 5.3v112017-09-19
CVE-2017-7145 [MEDIUM] CVE-2017-7145: iOS 11
Apple Security Update: About the security content of iOS 11
Product: iOS
Version: 11
CVE: CVE-2017-7145
Component: Time
Impact: "Setting Time Zone" may incorrectly indicate that it is using location
Description: A permissions issue existed in the process that handles time zone information. The issue was resolved by modifying permissions.
apple
CVE-2015-1062P4MEDIUMCVSS 5.0v8.2
CVE-2015-1062 [MEDIUM] CVE-2015-1062: iOS 8.2
Apple Security Update: About the security content of iOS 8.2
Product: iOS
Version: 8.2
CVE: CVE-2015-1062
Component: CVE-ID
apple