Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 100 of 207
CVE-2015-6990P3MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-6990 [MEDIUM] CVE-2015-6990: FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitr
FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7009, CVE-2015-7010, and CVE-2015-7018.
nvd
CVE-2015-7010P3MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-7010 [MEDIUM] CVE-2015-7010: FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitr
FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7009, and CVE-2015-7018.
nvd
CVE-2015-6977P3MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-6977 [MEDIUM] CVE-2015-6977: FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitr
FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7009, CVE-2015-7010, and CVE-2015-7018.
nvd
CVE-2015-6976P3MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-6976 [MEDIUM] CWE-119 CVE-2015-6976: FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitr
FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7009, CVE-2015-7010, and CVE-2015-7018.
nvd
CVE-2015-6993P3MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-6993 [MEDIUM] CVE-2015-6993: FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitr
FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-7008, CVE-2015-7009, CVE-2015-7010, and CVE-2015-7018.
nvd
CVE-2016-1758P4LOWCVSS 3.3PoC≤ 9.2.12016-03-24
CVE-2016-1758 [LOW] CWE-119 CVE-2016-1758: The kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to obtain sensitive memo
The kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to obtain sensitive memory-layout information or cause a denial of service (out-of-bounds read) via a crafted app.
nvd
CVE-2019-8567P3HIGHCVSS 7.5fixed in 12.22019-12-18
CVE-2019-8567 [HIGH] CWE-200 CVE-2019-8567: A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in iOS
A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in iOS 12.2. A device may be passively tracked by its WiFi MAC address.
nvd
CVE-2015-7107P3MEDIUMCVSS 6.8≤ 9.12015-12-11
CVE-2015-7107 [MEDIUM] CWE-119 CVE-2015-7107: QuickLook in Apple iOS before 9.2 and OS X before 10.11.2 allows remote attackers to execute arbitra
QuickLook in Apple iOS before 9.2 and OS X before 10.11.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted iWork file.
nvd
CVE-2014-4375P3HIGHCVSS 7.8≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4375 [HIGH] CVE-2014-4375: Double free vulnerability in Apple iOS before 8 and Apple TV before 7 allows local users to gain pri
Double free vulnerability in Apple iOS before 8 and Apple TV before 7 allows local users to gain privileges or cause a denial of service (device crash) via vectors related to Mach ports.
nvd
CVE-2019-8618P3HIGHCVSS 7.5fixed in 12.22020-10-27
CVE-2019-8618 [HIGH] CVE-2019-8618: A logic issue was addressed with improved restrictions. This issue is fixed in watchOS 5.2, macOS Mo
A logic issue was addressed with improved restrictions. This issue is fixed in watchOS 5.2, macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, iOS 12.2. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2016-1766P3HIGHCVSS 7.5≤ 9.2.12016-03-24
CVE-2016-1766 [HIGH] CVE-2016-1766: The Profiles component in Apple iOS before 9.3 does not properly validate certificates, which allows
The Profiles component in Apple iOS before 9.3 does not properly validate certificates, which allows attackers to spoof an MDM profile trust relationship via unspecified vectors.
nvd
CVE-2023-40443P3HIGHCVSS 7.8fixed in 17.02023-09-27
CVE-2023-40443 [HIGH] CVE-2023-40443: The issue was addressed with improved checks. This issue is fixed in iOS 17 and iPadOS 17. An app ma
The issue was addressed with improved checks. This issue is fixed in iOS 17 and iPadOS 17. An app may be able to gain root privileges.
nvd
CVE-2022-22673P3HIGHCVSS 7.5fixed in 15.42022-05-26
CVE-2022-22673 [HIGH] CVE-2022-22673: This issue was addressed with improved checks. This issue is fixed in iOS 15.5 and iPadOS 15.5. Proc
This issue was addressed with improved checks. This issue is fixed in iOS 15.5 and iPadOS 15.5. Processing a large input may lead to a denial of service.
nvd
CVE-2023-42977P3HIGHCVSS 7.8fixed in 17.02025-04-11
CVE-2023-42977 [HIGH] CWE-20 CVE-2023-42977: A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPad
A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to break out of its sandbox.
nvd
CVE-2023-42928P3HIGHCVSS 7.8fixed in 17.12024-02-21
CVE-2023-42928 [HIGH] CWE-276 CVE-2023-42928: The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.1 and iPadOS 17.1
The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.1 and iPadOS 17.1. An app may be able to gain elevated privileges.
nvd
CVE-2015-7015P3MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-7015 [MEDIUM] CWE-119 CVE-2015-7015: Heap-based buffer overflow in the DNS client library in configd in Apple iOS before 9.1, OS X before
Heap-based buffer overflow in the DNS client library in configd in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows attackers to execute arbitrary code via a crafted app that sends a spoofed configd response to a client.
nvd
CVE-2020-9823P3HIGHCVSS 7.5fixed in 13.52020-06-09
CVE-2020-9823 [HIGH] CVE-2020-9823: This issue was addressed with improved checks. This issue is fixed in iOS 13.5 and iPadOS 13.5. User
This issue was addressed with improved checks. This issue is fixed in iOS 13.5 and iPadOS 13.5. Users removed from an iMessage conversation may still be able to alter state.
nvd
CVE-2017-2498P3HIGHCVSS 7.5≤ 10.3.12017-05-22
CVE-2017-2498 [HIGH] CWE-295 CVE-2017-2498: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. The issue involves
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. The issue involves the "Security" component. It allows attackers to bypass intended access restrictions via an untrusted certificate.
nvd
CVE-2025-31207P3HIGHCVSS 7.7fixed in 18.52025-05-12
CVE-2025-31207 [HIGH] CWE-200 CVE-2025-31207: A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. A
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. An app may be able to enumerate a user's installed apps.
nvd
CVE-2018-4117P3MEDIUMCVSS 6.5fixed in 11.32018-04-03
CVE-2018-4117 [MEDIUM] CWE-200 CVE-2018-4117: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves the fetch API in the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy an
nvd