cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 103 of 207
CVE-2015-5926P4MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-5926 [MEDIUM] CVE-2015-5926: The CoreGraphics component in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 al The CoreGraphics component in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2015-5925.
nvd
CVE-2015-5925P4MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-5925 [MEDIUM] CWE-119 CVE-2015-5925: The CoreGraphics component in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 al The CoreGraphics component in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2015-5926.
nvd
CVE-2015-7065P4MEDIUMCVSS 6.8≤ 9.12015-12-11
CVE-2015-7065 [MEDIUM] CWE-119 CVE-2015-7065: OpenGL in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to OpenGL in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
nvd
CVE-2015-1104P4MEDIUMCVSS 5.0≤ 8.22015-04-10
CVE-2015-1104 [MEDIUM] CWE-20 CVE-2015-1104: The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 does not prop The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 does not properly determine whether an IPv6 packet had a local origin, which allows remote attackers to bypass an intended network-filtering protection mechanism via a crafted packet.
nvd
CVE-2015-5940P4MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-5940 [MEDIUM] CWE-119 CVE-2015-5940: The Accelerate Framework component in Apple iOS before 9.1 and OS X before 10.11.1, when multi-threa The Accelerate Framework component in Apple iOS before 9.1 and OS X before 10.11.1, when multi-threading is enabled, omits certain validation and locking steps, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
nvd
CVE-2015-5924P4MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-5924 [MEDIUM] CWE-119 CVE-2015-5924: The OpenGL implementation in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to The OpenGL implementation in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
nvd
CVE-2020-9952P4HIGHCVSS 7.1fixed in 14.02020-10-16
CVE-2020-9952 [HIGH] CWE-79 CVE-2020-9952: An input validation issue was addressed with improved input validation. This issue is fixed in iOS 1 An input validation issue was addressed with improved input validation. This issue is fixed in iOS 14.0 and iPadOS 14.0, tvOS 14.0, watchOS 7.0, Safari 14.0, iCloud for Windows 11.4, iCloud for Windows 7.21. Processing maliciously crafted web content may lead to a cross site scripting attack.
nvd
CVE-2016-1779P3MEDIUMCVSS 6.5≤ 9.2.12016-03-24
CVE-2016-1779 [MEDIUM] CWE-200 CVE-2016-1779: WebKit in Apple iOS before 9.3 and Safari before 9.1 allows remote attackers to bypass the Same Orig WebKit in Apple iOS before 9.3 and Safari before 9.1 allows remote attackers to bypass the Same Origin Policy and obtain physical-location data via a crafted geolocation request.
nvd
CVE-2018-4188P3MEDIUMCVSS 6.5fixed in 11.42018-06-08
CVE-2018-4188 [MEDIUM] CWE-20 CVE-2018-4188: An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to spoof the address bar via a crafted web site.
nvd
CVE-2021-30857P4HIGHCVSS 7.0fixed in 15.02021-08-24
CVE-2021-30857 [HIGH] CWE-362 CVE-2021-30857: A race condition was addressed with improved locking. This issue is fixed in Security Update 2021-00 A race condition was addressed with improved locking. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, tvOS 15, iOS 15 and iPadOS 15, watchOS 8, macOS Big Sur 11.6. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2025-31225P4HIGHCVSS 7.1fixed in 18.52025-05-12
CVE-2025-31225 [HIGH] CWE-200 CVE-2025-31225: A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.5 and iPadOS A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.5 and iPadOS 18.5. Call history from deleted apps may still appear in spotlight search results.
nvd
CVE-2022-32832P3MEDIUMCVSS 6.7fixed in 15.62022-09-23
CVE-2022-32832 [MEDIUM] CVE-2022-32832: The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15 The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app with root privileges may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2023-40416P4MEDIUMCVSS 6.5fixed in 16.7.2≥ 17.0, < 17.12023-10-25
CVE-2023-40416 [MEDIUM] CWE-119 CVE-2023-40416: The issue was addressed with improved memory handling. This issue is fixed in iOS 17.1 and iPadOS 17 The issue was addressed with improved memory handling. This issue is fixed in iOS 17.1 and iPadOS 17.1, macOS Monterey 12.7.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Ventura 13.6.1, macOS Sonoma 14.1. Processing an image may result in disclosure of process memory.
nvd
CVE-2019-8612P4MEDIUMCVSS 6.5fixed in 12.32020-10-27
CVE-2019-8612 [MEDIUM] CVE-2019-8612: A logic issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.1 A logic issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, tvOS 12.3, watchOS 5.2.1, macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3. An attacker in a privileged network position can modify
nvd
CVE-2026-43707P4MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-43707 [MEDIUM] CWE-119 CVE-2026-43707: A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-43745P4MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-43745 [MEDIUM] CWE-787 CVE-2026-43745: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Sa An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2025-43457P4MEDIUMCVSS 6.5fixed in 26.12025-11-04
CVE-2025-43457 [MEDIUM] CWE-416 CVE-2025-43457: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2026-43732P3MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-43732 [MEDIUM] CWE-22 CVE-2026-43732: A path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2, A path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may disclose sensitive user information.
nvd
CVE-2026-64735P4MEDIUMCVSS 6.5fixed in 26.62026-07-27
CVE-2026-64735 [MEDIUM] CWE-451 CVE-2026-64735: An inconsistent user interface issue was addressed with improved state management. This issue is fix An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote attacker may be able to bypass network filters.
nvd
CVE-2026-43740P4MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-43740 [MEDIUM] CWE-119 CVE-2026-43740: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26. The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may result in the disclosure of process memory.
nvd
Apple iOS vulnerabilities | cvebase