Apple iOS vulnerabilities
1,765 known vulnerabilities affecting apple/ios.
Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7
Vulnerabilities
Page 72 of 89
CVE-2022-32833P4MEDIUMCVSS 5.3≥ unspecified, < 162022-12-15
CVE-2022-32833 [MEDIUM] CWE-922 CVE-2022-32833: An issue existed with the file paths used to store website data. The issue was resolved by improving
An issue existed with the file paths used to store website data. The issue was resolved by improving how website data is stored. This issue is fixed in iOS 16. An unauthorized user may be able to access browsing history.
nvdapple
CVE-2022-32859P4MEDIUMCVSS 5.3≥ unspecified, < 162022-11-01
CVE-2022-32859 [MEDIUM] CWE-642 CVE-2022-32859: A logic issue was addressed with improved state management. This issue is fixed in iOS 16. Deleted c
A logic issue was addressed with improved state management. This issue is fixed in iOS 16. Deleted contacts may still appear in spotlight search results.
nvdapple
CVE-2017-13831P4HIGHCVSS 7.1v112017-09-19
CVE-2017-13831 [HIGH] CVE-2017-13831: iOS 11
Apple Security Update: About the security content of iOS 11
Product: iOS
Version: 11
CVE: CVE-2017-13831
Component: ImageIO
Impact: Processing a maliciously crafted image may lead to a denial of service
Description: A memory corruption issue was addressed with improved input validation.
apple
CVE-2016-1784P4MEDIUMCVSS 6.5v9.3
CVE-2016-1784 [MEDIUM] CVE-2016-1784: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2016-1784
Component: CVE-ID
apple
CVE-2016-7601P4MEDIUMCVSS 6.8v10.22016-12-12
CVE-2016-7601 [MEDIUM] CVE-2016-7601: iOS 10.2
Apple Security Update: About the security content of iOS 10.2
Product: iOS
Version: 10.2
CVE: CVE-2016-7601
Component: Local Authentication
Impact: The device may not lock the screen after the idle timeout
Description: A logic issue existed in the handling of the idle timer when the Touch ID prompt is shown. This issue was addressed through improved handling of the idle timer.
apple
CVE-2017-2495P4MEDIUMCVSS 6.5v10.3.22017-05-15
CVE-2017-2495 [MEDIUM] CVE-2017-2495: iOS 10.3.2
Apple Security Update: About the security content of iOS 10.3.2
Product: iOS
Version: 10.3.2
CVE: CVE-2017-2495
Component: Safari
Impact: Visiting a maliciously crafted webpage may lead to an application denial of service
Description: An issue in Safari's history menu was addressed through improved memory handling.
apple
CVE-2015-7995P4MEDIUMCVSS 5.0v9.2.1
CVE-2015-7995 [MEDIUM] CVE-2015-7995: iOS 9.2.1
Apple Security Update: About the security content of iOS 9.2.1
Product: iOS
Version: 9.2.1
CVE: CVE-2015-7995
Component: CVE-ID
Impact: A local user may be able to execute arbitrary code with root privileges
Description: A memory corruption issue was addressed through improved memory handling.
apple
CVE-2016-7636P4MEDIUMCVSS 5.9v10.22016-12-12
CVE-2016-7636 [MEDIUM] CVE-2016-7636: iOS 10.2
Apple Security Update: About the security content of iOS 10.2
Product: iOS
Version: 10.2
CVE: CVE-2016-7636
Component: Security
Impact: An attacker in a privileged network position may be able to cause a denial of service
Description: A validation issue existed in the handling of OCSP responder URLs. This issue was addressed by verifying OCSP revocation status after CA validation and limiting the number of OCSP requests per certificate.
apple
CVE-2019-6228P4MEDIUMCVSS 6.1≥ unspecified, < iOS 12.1.32019-03-05
CVE-2019-6228 [MEDIUM] CWE-79 CVE-2019-6228: A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validatio
A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue is fixed in iOS 12.1.3, Safari 12.0.3. Processing maliciously crafted web content may lead to a cross site scripting attack.
nvdapple
CVE-2016-7762P4MEDIUMCVSS 6.1v10.22016-12-12
CVE-2016-7762 [MEDIUM] CVE-2016-7762: iOS 10.2
Apple Security Update: About the security content of iOS 10.2
Product: iOS
Version: 10.2
CVE: CVE-2016-7762
Component: WebKit
Impact: Processing maliciously crafted web content may lead to cross site scripting
Description: An issue existed in displaying documents in Safari. This issue was addressed through improved input validation.
apple
CVE-2019-8582P4MEDIUMCVSS 5.5≥ unspecified, < 12.32020-10-27
CVE-2019-8582 [MEDIUM] CWE-125 CVE-2019-8582: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iCloud for
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iCloud for Windows 7.12, tvOS 12.3, iTunes 12.9.5 for Windows, macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3. Processing a maliciously crafted font may result in the disclosure of process memory.
nvdapple
CVE-2019-8789P4MEDIUMCVSS 5.5≥ unspecified, < iOS 13.2 and iPadOS 13.22019-12-18
CVE-2019-8789 [MEDIUM] CWE-59 CVE-2019-8789: A validation issue existed in the handling of symlinks. This issue was addressed with improved valid
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1. Parsing a maliciously crafted iBooks file may lead to disclosure of user information.
nvd
CVE-2020-9968P4MEDIUMCVSS 5.5≥ unspecified, < iOS 14.0 and iPadOS 14.02020-10-16
CVE-2020-9968 [MEDIUM] CVE-2020-9968: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 14.0 and iPadOS 1
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 14.0 and iPadOS 14.0, macOS Catalina 10.15.7, tvOS 14.0, watchOS 7.0. A malicious application may be able to access restricted files.
nvd
CVE-2020-9902P4MEDIUMCVSS 5.5≥ unspecified, < iOS 13.6 and iPadOS 13.62020-10-22
CVE-2020-9902 [MEDIUM] CWE-125 CVE-2020-9902: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 a
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A malicious application may be able to determine kernel memory layout.
nvd
CVE-2016-4604P4MEDIUMCVSS 5.4v9.3.32016-07-18
CVE-2016-4604 [MEDIUM] CVE-2016-4604: iOS 9.3.3
Apple Security Update: About the security content of iOS 9.3.3
Product: iOS
Version: 9.3.3
CVE: CVE-2016-4604
Component: Safari
Impact: Visiting a malicious website may lead to user interface spoofing
Description: Redirect responses to invalid ports may have allowed a malicious website to display an arbitrary domain while displaying arbitrary content. This issue was addressed through improved URL display logic.
apple
CVE-2016-1786P4MEDIUMCVSS 5.4v9.3
CVE-2016-1786 [MEDIUM] CVE-2016-1786: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2016-1786
Component: CVE-ID
apple
CVE-2019-8744P4MEDIUMCVSS 5.5≥ unspecified, < 132020-10-27
CVE-2019-8744 [MEDIUM] CWE-787 CVE-2019-8744: A memory corruption issue existed in the handling of IPv6 packets. This issue was addressed with imp
A memory corruption issue existed in the handling of IPv6 packets. This issue was addressed with improved memory management. This issue is fixed in macOS Catalina 10.15, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6, iOS 13. A malicious application may be able to determine kernel memory layout.
nvdapple
CVE-2019-6207P4MEDIUMCVSS 5.5≥ unspecified, < iOS 12.22019-12-18
CVE-2019-6207 [MEDIUM] CWE-125 CVE-2019-6207: An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to determine kernel memory layout.
nvdapple
CVE-2015-1084P4MEDIUMCVSS 5.0v8.3
CVE-2015-1084 [MEDIUM] CVE-2015-1084: iOS 8.3
Apple Security Update: About the security content of iOS 8.3
Product: iOS
Version: 8.3
CVE: CVE-2015-1084
Component: CVE-ID
apple
CVE-2018-4356P4MEDIUMCVSS 5.3v122018-09-17
CVE-2018-4356 [MEDIUM] CVE-2018-4356: iOS 12
Apple Security Update: About the security content of iOS 12
Product: iOS
Version: 12
CVE: CVE-2018-4356
Component: CoreMedia
Impact: An app may be able to learn information about the current camera view before being granted camera access
Description: A permissions issue existed. This issue was addressed with improved permission validation.
apple