Apple iOS vulnerabilities
1,765 known vulnerabilities affecting apple/ios.
Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7
Vulnerabilities
Page 78 of 89
CVE-2015-3755P4MEDIUMCVSS 4.3v8.4.1
CVE-2015-3755 [MEDIUM] CVE-2015-3755: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-3755
Component: CVE-ID
apple
CVE-2016-7592P4MEDIUMCVSS 4.3v10.22016-12-12
CVE-2016-7592 [MEDIUM] CVE-2016-7592: iOS 10.2
Apple Security Update: About the security content of iOS 10.2
Product: iOS
Version: 10.2
CVE: CVE-2016-7592
Component: WebKit
Impact: Processing maliciously crafted web content may compromise user information
Description: An issue existed in handling of JavaScript prompts. This was addressed through improved state management.
apple
CVE-2015-3758P4MEDIUMCVSS 4.3v8.4.1
CVE-2015-3758 [MEDIUM] CVE-2015-3758: iOS 8.4.1
Apple Security Update: About the security content of iOS 8.4.1
Product: iOS
Version: 8.4.1
CVE: CVE-2015-3758
Component: CVE-ID
apple
CVE-2020-3887P4MEDIUMCVSS 4.3≥ unspecified, < iOS 13.4 and iPadOS 13.42020-04-01
CVE-2020-3887 [MEDIUM] CVE-2020-3887: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 1
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. A download's origin may be incorrectly associated.
nvd
CVE-2017-13873P4MEDIUMCVSS 4.3v112017-09-19
CVE-2017-13873 [MEDIUM] CVE-2017-13873: iOS 11
Apple Security Update: About the security content of iOS 11
Product: iOS
Version: 11
CVE: CVE-2017-13873
Component: Kernel
Impact: A malicious application may be able to learn information about the presence and operation of other applications on the device.
Description: An application was able to access network activity information maintained by the operating system unrestricted. This issue was addressed by reducing the information available to thir
apple
CVE-2022-1622P4MEDIUMCVSS 5.5v162022-09-12
CVE-2022-1622 [MEDIUM] CVE-2022-1622: iOS 16
Apple Security Update: About the security content of iOS 16
Product: iOS
Version: 16
CVE: CVE-2022-1622
Component: CVE-2022-1622
apple
CVE-2017-7173P4MEDIUMCVSS 5.5v11.22017-12-02
CVE-2017-7173 [MEDIUM] CVE-2017-7173: iOS 11.2
Apple Security Update: About the security content of iOS 11.2
Product: iOS
Version: 11.2
CVE: CVE-2017-7173
Component: Kernel
Impact: An application may be able to read restricted memory
Description: An out-of-bounds read was addressed with improved bounds checking.
apple
CVE-2020-9976P4MEDIUMCVSS 5.5≥ unspecified, < iOS 14.0 and iPadOS 14.02020-10-16
CVE-2020-9976 [MEDIUM] CVE-2020-9976: A logic issue was addressed with improved state management. This issue is fixed in iOS 14.0 and iPad
A logic issue was addressed with improved state management. This issue is fixed in iOS 14.0 and iPadOS 14.0, tvOS 14.0, watchOS 7.0. A malicious application may be able to leak sensitive user information.
nvd
CVE-2018-4363P4MEDIUMCVSS 5.5v122018-09-17
CVE-2018-4363 [MEDIUM] CVE-2018-4363: iOS 12
Apple Security Update: About the security content of iOS 12
Product: iOS
Version: 12
CVE: CVE-2018-4363
Component: Kernel
Impact: An application may be able to read restricted memory
Description: An input validation issue existed in the kernel. This issue was addressed with improved input validation.
apple
CVE-2018-4391P4MEDIUMCVSS 5.5v12.12018-10-30
CVE-2018-4391 [MEDIUM] CVE-2018-4391: iOS 12.1
Apple Security Update: About the security content of iOS 12.1
Product: iOS
Version: 12.1
CVE: CVE-2018-4391
Component: Messages
Impact: Processing a maliciously crafted text message may lead to UI spoofing
Description: An inconsistent user interface issue was addressed with improved state management.
apple
CVE-2018-4390P4MEDIUMCVSS 5.5v11.32018-03-29
CVE-2018-4390 [MEDIUM] CVE-2018-4390: iOS 11.3
Apple Security Update: About the security content of iOS 11.3
Product: iOS
Version: 11.3
CVE: CVE-2018-4390
Component: LinkPresentation
Impact: Visiting a malicious website may lead to address bar spoofing
Description: An inconsistent user interface issue was addressed with improved state management.
apple
CVE-2018-4355P4MEDIUMCVSS 5.5v122018-09-17
CVE-2018-4355 [MEDIUM] CVE-2018-4355: iOS 12
Apple Security Update: About the security content of iOS 12
Product: iOS
Version: 12
CVE: CVE-2018-4355
Component: Heimdal
Impact: An application may be able to execute arbitrary code with system privileges
Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2018-4333P4MEDIUMCVSS 5.5v122018-09-17
CVE-2018-4333 [MEDIUM] CVE-2018-4333: iOS 12
Apple Security Update: About the security content of iOS 12
Product: iOS
Version: 12
CVE: CVE-2018-4333
Component: Crash Reporter
Impact: An application may be able to read restricted memory
Description: A validation issue was addressed with improved input sanitization.
apple
CVE-2017-6976P4MEDIUMCVSS 5.5v10.32017-03-27
CVE-2017-6976 [MEDIUM] CVE-2017-6976: iOS 10.3
Apple Security Update: About the security content of iOS 10.3
Product: iOS
Version: 10.3
CVE: CVE-2017-6976
Component: Sandbox Profiles
Impact: A malicious application may be able to access the iCloud user record of a signed in user
Description: An access issue was addressed through additional sandbox restrictions on third party applications.
apple
CVE-2017-7131P4MEDIUMCVSS 5.5v112017-09-19
CVE-2017-7131 [MEDIUM] CVE-2017-7131: iOS 11
Apple Security Update: About the security content of iOS 11
Product: iOS
Version: 11
CVE: CVE-2017-7131
Component: Bluetooth
Impact: An application may be able to access restricted files
Description: A privacy issue existed in the handling of Contact cards. This was addressed with improved state management.
apple
CVE-2015-1118P4MEDIUMCVSS 5.0v8.3
CVE-2015-1118 [MEDIUM] CVE-2015-1118: iOS 8.3
Apple Security Update: About the security content of iOS 8.3
Product: iOS
Version: 8.3
CVE: CVE-2015-1118
Component: CVE-ID
apple
CVE-2017-13806P4MEDIUMCVSS 5.5v112017-09-19
CVE-2017-13806 [MEDIUM] CVE-2017-13806: iOS 11
Apple Security Update: About the security content of iOS 11
Product: iOS
Version: 11
CVE: CVE-2017-13806
Component: Profiles
Impact: Device pairing records could be inadvertently installed on a device when a profile that disallows pairing is installed
Description: Pairings were not removed when a profile disallowing pairings was installed. This was addressed by removing pairings conflicting with the configuration profile.
apple
CVE-2020-9885P4MEDIUMCVSS 5.5≥ unspecified, < iOS 13.6 and iPadOS 13.62020-10-16
CVE-2020-9885 [MEDIUM] CWE-345 CVE-2020-9885: An issue existed in the handling of iMessage tapbacks. The issue was resolved with additional verifi
An issue existed in the handling of iMessage tapbacks. The issue was resolved with additional verification. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A user that is removed from an iMessage group could rejoin the group.
nvd
CVE-2018-4313P4MEDIUMCVSS 5.5v122018-09-17
CVE-2018-4313 [MEDIUM] CVE-2018-4313: iOS 12
Apple Security Update: About the security content of iOS 12
Product: iOS
Version: 12
CVE: CVE-2018-4313
Component: Messages
Impact: A local user may be able to discover a user’s deleted messages
Description: A consistency issue existed in the handling of application snapshots. The issue was addressed with improved handling of message deletions.
apple
CVE-2020-3917P4MEDIUMCVSS 5.5≥ unspecified, < iOS 13.4 and iPadOS 13.42020-04-01
CVE-2020-3917 [MEDIUM] CVE-2020-3917: This issue was addressed with a new entitlement. This issue is fixed in iOS 13.4 and iPadOS 13.4, tv
This issue was addressed with a new entitlement. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, watchOS 6.2. An application may be able to use an SSH client provided by private frameworks.
nvd