Apple iOS vulnerabilities
1,765 known vulnerabilities affecting apple/ios.
Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7
Vulnerabilities
Page 81 of 89
CVE-2018-4216P4MEDIUMCVSS 5.5v11.4.12018-07-09
CVE-2018-4216 [MEDIUM] CVE-2018-4216: iOS 11.4.1
Apple Security Update: About the security content of iOS 11.4.1
Product: iOS
Version: 11.4.1
CVE: CVE-2018-4216
Component: Phone
Impact: A malicious application may be able to bypass the call confirmation prompt
Description: A logic issue existed in the handling of call URLs. This issue was addressed with improved state management.
apple
CVE-2018-4395P4MEDIUMCVSS 5.5v122018-09-17
CVE-2018-4395 [MEDIUM] CVE-2018-4395: iOS 12
Apple Security Update: About the security content of iOS 12
Product: iOS
Version: 12
CVE: CVE-2018-4395
Component: Security
Impact: A local user may be able to cause a denial of service
Description: This issue was addressed with improved checks.
apple
CVE-2016-4628P4MEDIUMCVSS 5.5v9.3.32016-07-18
CVE-2016-4628 [MEDIUM] CVE-2016-4628: iOS 9.3.3
Apple Security Update: About the security content of iOS 9.3.3
Product: iOS
Version: 9.3.3
CVE: CVE-2016-4628
Component: IOAcceleratorFamily
Impact: A local user may be able to read kernel memory
Description: An out-of-bounds read was addressed through improved bounds checking.
apple
CVE-2015-1090P4MEDIUMCVSS 5.0v8.3
CVE-2015-1090 [MEDIUM] CVE-2015-1090: iOS 8.3
Apple Security Update: About the security content of iOS 8.3
Product: iOS
Version: 8.3
CVE: CVE-2015-1090
Component: CVE-2015-1090
apple
CVE-2018-4278P4MEDIUMCVSS 4.3v11.4.12018-07-09
CVE-2018-4278 [MEDIUM] CVE-2018-4278: iOS 11.4.1
Apple Security Update: About the security content of iOS 11.4.1
Product: iOS
Version: 11.4.1
CVE: CVE-2018-4278
Component: WebKit
Impact: A malicious website may exfiltrate audio data cross-origin
Description: Sound fetched through audio elements may be exfiltrated cross-origin. This issue was addressed with improved audio taint tracking.
apple
CVE-2015-7050P4MEDIUMCVSS 4.3v9.2
CVE-2015-7050 [MEDIUM] CVE-2015-7050: iOS 9.2
Apple Security Update: About the security content of iOS 9.2
Product: iOS
Version: 9.2
CVE: CVE-2015-7050
Component: CVE-ID
apple
CVE-2015-3725P4MEDIUMCVSS 4.3v8.4
CVE-2015-3725 [MEDIUM] CVE-2015-3725: iOS 8.4
Apple Security Update: About the security content of iOS 8.4
Product: iOS
Version: 8.4
CVE: CVE-2015-3725
Component: CVE-ID
apple
CVE-2015-3690P4MEDIUMCVSS 4.3v8.4
CVE-2015-3690 [MEDIUM] CVE-2015-3690: iOS 8.4
Apple Security Update: About the security content of iOS 8.4
Product: iOS
Version: 8.4
CVE: CVE-2015-3690
Component: CVE-ID
apple
CVE-2015-1125P4MEDIUMCVSS 4.3v8.3
CVE-2015-1125 [MEDIUM] CVE-2015-1125: iOS 8.3
Apple Security Update: About the security content of iOS 8.3
Product: iOS
Version: 8.3
CVE: CVE-2015-1125
Component: CVE-ID
apple
CVE-2015-7093P4MEDIUMCVSS 4.3v9.2
CVE-2015-7093 [MEDIUM] CVE-2015-7093: iOS 9.2
Apple Security Update: About the security content of iOS 9.2
Product: iOS
Version: 9.2
CVE: CVE-2015-7093
Component: CVE-ID
apple
CVE-2017-7144P4MEDIUMCVSS 4.3v112017-09-19
CVE-2017-7144 [MEDIUM] CVE-2017-7144: iOS 11
Apple Security Update: About the security content of iOS 11
Product: iOS
Version: 11
CVE: CVE-2017-7144
Component: WebKit
Impact: A malicious website may be able to track users in Safari private browsing mode
Description: A permissions issue existed in the handling of web browser cookies. This issue was addressed with improved restrictions.
apple
CVE-2019-8769P4MEDIUMCVSS 4.3≥ unspecified, < iOS 13.1 and iPadOS 13.12019-12-18
CVE-2019-8769 [MEDIUM] CVE-2019-8769: An issue existed in the drawing of web page elements. The issue was addressed with improved logic. T
An issue existed in the drawing of web page elements. The issue was addressed with improved logic. This issue is fixed in iOS 13.1 and iPadOS 13.1, macOS Catalina 10.15. Visiting a maliciously crafted website may reveal browsing history.
nvd
CVE-2014-4467P4MEDIUMCVSS 4.3v8.1.3
CVE-2014-4467 [MEDIUM] CVE-2014-4467: iOS 8.1.3
Apple Security Update: About the security content of iOS 8.1.3
Product: iOS
Version: 8.1.3
CVE: CVE-2014-4467
Component: CVE-ID
apple
CVE-2017-7152P4MEDIUMCVSS 4.3v11.22017-12-02
CVE-2017-7152 [MEDIUM] CVE-2017-7152: iOS 11.2
Apple Security Update: About the security content of iOS 11.2
Product: iOS
Version: 11.2
CVE: CVE-2017-7152
Component: Mail Message Framework
Impact: Visiting a malicious website may lead to address bar spoofing
Description: An inconsistent user interface issue was addressed with improved state management.
apple
CVE-2022-32868P4MEDIUMCVSS 4.3≥ unspecified, < 162022-09-20
CVE-2022-32868 [MEDIUM] CVE-2022-32868: A logic issue was addressed with improved state management. This issue is fixed in Safari 16, iOS 16
A logic issue was addressed with improved state management. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. A website may be able to track users through Safari web extensions.
nvdapple
CVE-2015-8035P4MEDIUMCVSS 5.0v9.3
CVE-2015-8035 [MEDIUM] CVE-2015-8035: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2015-8035
Component: CVE-2015-7499
apple
CVE-2017-2368P4MEDIUMCVSS 5.5v10.2.12017-01-23
CVE-2017-2368 [MEDIUM] CVE-2017-2368: iOS 10.2.1
Apple Security Update: About the security content of iOS 10.2.1
Product: iOS
Version: 10.2.1
CVE: CVE-2017-2368
Component: Contacts
Impact: Processing a maliciously crafted contact card may lead to unexpected application termination
Description: An input validation issue existed in the parsing of contact cards. This issue was addressed through improved input validation.
apple
CVE-2018-4400P4MEDIUMCVSS 5.5v12.12018-10-30
CVE-2018-4400 [MEDIUM] CVE-2018-4400: iOS 12.1
Apple Security Update: About the security content of iOS 12.1
Product: iOS
Version: 12.1
CVE: CVE-2018-4400
Component: Security
Impact: Processing a maliciously crafted S/MIME signed message may lead to a denial of service
Description: A validation issue was addressed with improved logic.
apple
CVE-2019-8538P4MEDIUMCVSS 5.5≥ unspecified, < 12.22020-10-27
CVE-2019-8538 [MEDIUM] CVE-2019-8538: A denial of service issue was addressed with improved validation. This issue is fixed in watchOS 5.2
A denial of service issue was addressed with improved validation. This issue is fixed in watchOS 5.2, macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, iOS 12.2. Processing a maliciously crafted vcf file may lead to a denial of service.
nvdapple
CVE-2017-7097P4MEDIUMCVSS 5.5v112017-09-19
CVE-2017-7097 [MEDIUM] CVE-2017-7097: iOS 11
Apple Security Update: About the security content of iOS 11
Product: iOS
Version: 11
CVE: CVE-2017-7097
Component: Mail MessageUI
Impact: Processing a maliciously crafted image may lead to a denial of service
Description: A memory corruption issue was addressed with improved validation.
apple