Apple iOS vulnerabilities
1,765 known vulnerabilities affecting apple/ios.
Total CVEs
1,765
CISA KEV
27
actively exploited
Public exploits
229
Exploited in wild
43
Severity breakdown
CRITICAL119HIGH907MEDIUM638LOW94UNKNOWN7
Vulnerabilities
Page 83 of 89
CVE-2016-7634P4MEDIUMCVSS 4.6v10.22016-12-12
CVE-2016-7634 [MEDIUM] CVE-2016-7634: iOS 10.2
Apple Security Update: About the security content of iOS 10.2
Product: iOS
Version: 10.2
CVE: CVE-2016-7634
Component: Accessibility
Impact: A nearby user may be able to overhear spoken passwords
Description: A disclosure issue existed in the handling of passwords. This issue was addressed by disabling the speaking of passwords.
apple
CVE-2018-4252P4MEDIUMCVSS 4.6v11.42018-05-29
CVE-2018-4252 [MEDIUM] CVE-2018-4252: iOS 11.4
Apple Security Update: About the security content of iOS 11.4
Product: iOS
Version: 11.4
CVE: CVE-2018-4252
Component: Siri
Impact: A person with physical access to an iOS device may be able to use Siri to read notifications of content that is set not to be displayed at the lock screen
Description: An issue existed with Siri permissions. This was addressed with improved permission checking.
apple
CVE-2019-6222P4MEDIUMCVSS 4.3≥ unspecified, < iOS 12.22019-12-18
CVE-2019-6222 [MEDIUM] CVE-2019-6222: A consistency issue was addressed with improved state handling. This issue is fixed in iOS 12.2. A w
A consistency issue was addressed with improved state handling. This issue is fixed in iOS 12.2. A website may be able to access the microphone without the microphone use indicator being shown.
nvdapple
CVE-2015-6997P4MEDIUMCVSS 4.3v9.1
CVE-2015-6997 [MEDIUM] CVE-2015-6997: iOS 9.1
Apple Security Update: About the security content of iOS 9.1
Product: iOS
Version: 9.1
CVE: CVE-2015-6997
Component: CVE-ID
apple
CVE-2019-8727P4MEDIUMCVSS 4.3≥ unspecified, < iOS 132019-12-18
CVE-2019-8727 [MEDIUM] CVE-2019-8727: A logic issue was addressed with improved state management. This issue is fixed in iOS 13. Visiting
A logic issue was addressed with improved state management. This issue is fixed in iOS 13. Visiting a malicious website may lead to address bar spoofing.
nvdapple
CVE-2016-7581P4MEDIUMCVSS 4.3v10.12016-10-24
CVE-2016-7581 [MEDIUM] CVE-2016-7581: iOS 10.1
Apple Security Update: About the security content of iOS 10.1
Product: iOS
Version: 10.1
CVE: CVE-2016-7581
Component: Safari
Impact: A malicious website may be able to cause a denial-of-service
Description: A denial of service issue was addressed through improved URL handling.
apple
CVE-2022-32795P4MEDIUMCVSS 4.3≥ unspecified, < 162022-09-20
CVE-2022-32795 [MEDIUM] CVE-2022-32795: This issue was addressed with improved checks. This issue is fixed in iOS 16, iOS 15.7 and iPadOS 15
This issue was addressed with improved checks. This issue is fixed in iOS 16, iOS 15.7 and iPadOS 15.7. Visiting a malicious website may lead to address bar spoofing.
nvdapple
CVE-2016-4686P4MEDIUMCVSS 4.4v10.12016-10-24
CVE-2016-4686 [MEDIUM] CVE-2016-4686: iOS 10.1
Apple Security Update: About the security content of iOS 10.1
Product: iOS
Version: 10.1
CVE: CVE-2016-4686
Component: Contacts
Impact: An application may be able to maintain access to the Address Book after access is revoked in Settings
Description: An access control issue in the Address Book was addressed through improved file-link validation.
apple
CVE-2016-4707P4MEDIUMCVSS 4.0v102016-09-13
CVE-2016-4707 [MEDIUM] CVE-2016-4707: iOS 10
Apple Security Update: About the security content of iOS 10
Product: iOS
Version: 10
CVE: CVE-2016-4707
Component: CFNetwork
Impact: A local user may be able to discover websites a user has visited
Description: An issue existed in Local Storage deletion. This issue was addressed through improved Local Storage cleanup.
apple
CVE-2016-9642P4MEDIUMCVSS 5.5v10.32017-03-27
CVE-2016-9642 [MEDIUM] CVE-2016-9642: iOS 10.3
Apple Security Update: About the security content of iOS 10.3
Product: iOS
Version: 10.3
CVE: CVE-2016-9642
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed through improved input validation.
apple
CVE-2018-4304P4MEDIUMCVSS 5.0v122018-09-17
CVE-2018-4304 [MEDIUM] CVE-2018-4304: iOS 12
Apple Security Update: About the security content of iOS 12
Product: iOS
Version: 12
CVE: CVE-2018-4304
Component: Text
Impact: Processing a maliciously crafted text file may lead to a denial of service
Description: A denial of service issue was addressed with improved validation.
apple
CVE-2018-4239P4MEDIUMCVSS 4.6v11.42018-05-29
CVE-2018-4239 [MEDIUM] CVE-2018-4239: iOS 11.4
Apple Security Update: About the security content of iOS 11.4
Product: iOS
Version: 11.4
CVE: CVE-2018-4239
Component: Magnifier
Impact: A person with physical access to an iOS device may be able to view the last image used in Magnifier from the lockscreen
Description: A permissions issue existed in Magnifier. This was addressed with additional permission checks.
apple
CVE-2017-2352P4MEDIUMCVSS 4.6v10.2.12017-01-23
CVE-2017-2352 [MEDIUM] CVE-2017-2352: iOS 10.2.1
Apple Security Update: About the security content of iOS 10.2.1
Product: iOS
Version: 10.2.1
CVE: CVE-2017-2352
Component: Unlock with iPhone
Impact: Apple Watch may unlock when off the user’s wrist
Description: A logic issue was addressed through improved state management.
apple
CVE-2018-4244P4MEDIUMCVSS 4.6v11.42018-05-29
CVE-2018-4244 [MEDIUM] CVE-2018-4244: iOS 11.4
Apple Security Update: About the security content of iOS 11.4
Product: iOS
Version: 11.4
CVE: CVE-2018-4244
Component: Siri Contacts
Impact: An attacker with physical access to a device may be able to see private contact information
Description: An issue existed with Siri permissions. This was addressed with improved permission checking.
apple
CVE-2017-2452P4MEDIUMCVSS 4.6v10.32017-03-27
CVE-2017-2452 [MEDIUM] CVE-2017-2452: iOS 10.3
Apple Security Update: About the security content of iOS 10.3
Product: iOS
Version: 10.3
CVE: CVE-2017-2452
Component: Siri
Impact: Siri might reveal text message contents while the device is locked
Description: An insufficient locking issue was addressed with improved state management.
apple
CVE-2018-4388P4MEDIUMCVSS 4.6v12.12018-10-30
CVE-2018-4388 [MEDIUM] CVE-2018-4388: iOS 12.1
Apple Security Update: About the security content of iOS 12.1
Product: iOS
Version: 12.1
CVE: CVE-2018-4388
Component: Notes
Impact: A local attacker may be able to share items from the lock screen
Description: A lock screen issue allowed access to the share function on a locked device. This issue was addressed by restricting options offered on a locked device.
apple
CVE-2017-2399P4MEDIUMCVSS 4.6v10.32017-03-27
CVE-2017-2399 [MEDIUM] CVE-2017-2399: iOS 10.3
Apple Security Update: About the security content of iOS 10.3
Product: iOS
Version: 10.3
CVE: CVE-2017-2399
Component: CVE-2017-2399
apple
CVE-2015-1115P4MEDIUMCVSS 4.4v8.3
CVE-2015-1115 [MEDIUM] CVE-2015-1115: iOS 8.3
Apple Security Update: About the security content of iOS 8.3
Product: iOS
Version: 8.3
CVE: CVE-2015-1115
Component: CVE-ID
apple
CVE-2016-7638P4MEDIUMCVSS 4.6v10.22016-12-12
CVE-2016-7638 [MEDIUM] CVE-2016-7638: iOS 10.2
Apple Security Update: About the security content of iOS 10.2
Product: iOS
Version: 10.2
CVE: CVE-2016-7638
Component: Find My iPhone
Impact: An attacker with an unlocked device may be able to disable Find My iPhone
Description: A state management issue existed in the handling of authentication information. This issue was addressed through improved storage of account information.
apple
CVE-2016-7597P4MEDIUMCVSS 4.6v10.22016-12-12
CVE-2016-7597 [MEDIUM] CVE-2016-7597: iOS 10.2
Apple Security Update: About the security content of iOS 10.2
Product: iOS
Version: 10.2
CVE: CVE-2016-7597
Component: SpringBoard
Impact: A person with physical access to an iOS device may be able to keep the device unlocked
Description: A cleanup issue existed in the handling of Handoff with Siri. This was addressed through improved state management.
apple