cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 104 of 207
CVE-2025-43507P4MEDIUMCVSS 6.5fixed in 26.12025-11-04
CVE-2025-43507 [MEDIUM] CWE-276 CVE-2025-43507: A privacy issue was addressed by moving sensitive data. This issue is fixed in iOS 18.7.2 and iPadOS A privacy issue was addressed by moving sensitive data. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. An app may be able to fingerprint the user.
nvd
CVE-2026-64743P4MEDIUMCVSS 6.5fixed in 26.62026-07-27
CVE-2026-64743 [MEDIUM] CWE-285 CVE-2026-64743: An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.6 An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.
nvd
CVE-2011-1417P4MEDIUMCVSS 6.8≤ 4.2.5v1.0.0+28 more2011-03-11
CVE-2011-1417 [MEDIUM] CWE-189 CVE-2011-1417: Integer overflow in QuickLook, as used in Apple Mac OS X before 10.6.7 and MobileSafari in Apple iOS Integer overflow in QuickLook, as used in Apple Mac OS X before 10.6.7 and MobileSafari in Apple iOS before 4.2.7 and 4.3.x before 4.3.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a Microsoft Office document with a crafted size field in the OfficeArtMetafileHeader, rela
nvd
CVE-2011-0162P4HIGHCVSS 7.8≤ 4.2v1.0.0+28 more2011-03-11
CVE-2011-0162 [HIGH] CWE-20 CVE-2011-0162: Wi-Fi in Apple iOS before 4.3 and Apple TV before 4.2 does not properly perform bounds checking for Wi-Fi in Apple iOS before 4.3 and Apple TV before 4.2 does not properly perform bounds checking for Wi-Fi frames, which allows remote attackers to cause a denial of service (device reset) via unspecified traffic on the local wireless network.
nvd
CVE-2025-43210P4MEDIUMCVSS 6.3fixed in 18.62026-04-02
CVE-2025-43210 [MEDIUM] CWE-125 CVE-2025-43210: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
nvd
CVE-2013-5140P4HIGHCVSS 7.8≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-5140 [HIGH] CWE-20 CVE-2013-5140: The kernel in Apple iOS before 7 allows remote attackers to cause a denial of service (assertion fai The kernel in Apple iOS before 7 allows remote attackers to cause a denial of service (assertion failure and device restart) via an invalid packet fragment.
nvd
CVE-2009-0040P4MEDIUMCVSS 6.8fixed in 3.02009-02-22
CVE-2009-0040 [MEDIUM] CWE-824 CVE-2009-0040: The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush a The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file that triggers a free of an uninitialized pointer in (1) the png_read_png function, (2) p
nvd
CVE-2017-7063P4HIGHCVSS 7.5≤ 10.3.22017-07-20
CVE-2017-7063 [HIGH] CWE-400 CVE-2017-7063: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. watchOS before 3.2 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. watchOS before 3.2.3 is affected. The issue involves the "Messages" component. It allows remote attackers to cause a denial of service (memory consumption and application crash).
nvd
CVE-2015-1103P4HIGHCVSS 7.5≤ 8.22015-04-10
CVE-2015-1103 [HIGH] CWE-20 CVE-2015-1103: The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 makes routing The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 makes routing changes in response to ICMP_REDIRECT messages, which allows remote attackers to cause a denial of service (network outage) or obtain sensitive packet-content information via a crafted ICMP packet.
nvd
CVE-2010-1814P4MEDIUMCVSS 6.8fixed in 4.12010-09-09
CVE-2010-1814 [MEDIUM] CWE-119 CVE-2010-1814: WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remo WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors involving form menus.
nvd
CVE-2017-7007P4HIGHCVSS 7.5≤ 10.3.22017-07-20
CVE-2017-7007 [HIGH] CWE-400 CVE-2017-7007: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. The issue involves An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. The issue involves the "EventKitUI" component. It allows remote attackers to cause a denial of service (resource consumption and application crash).
nvd
CVE-2014-3192P4HIGHCVSS 7.5≤ 8.1.22014-10-08
CVE-2014-3192 [HIGH] CWE-416 CVE-2014-3192: Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/Pro Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.cpp in the DOM implementation in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2018-4371P4HIGHCVSS 7.8fixed in 12.12019-04-03
CVE-2018-4371 [HIGH] CWE-125 CVE-2018-4371: An out-of-bounds read was addressed with improved input validation. This issue affected versions pri An out-of-bounds read was addressed with improved input validation. This issue affected versions prior to iOS 12.1, macOS Mojave 10.14.1, tvOS 12.1, watchOS 5.1.
nvd
CVE-2015-5755P4MEDIUMCVSS 6.8≤ 8.42015-08-17
CVE-2015-5755 [MEDIUM] CWE-119 CVE-2015-5755: CoreText in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitr CoreText in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-5761.
nvd
CVE-2015-5761P4MEDIUMCVSS 6.8≤ 8.42015-08-17
CVE-2015-5761 [MEDIUM] CVE-2015-5761: CoreText in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitr CoreText in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-5755.
nvd
CVE-2015-5778P4MEDIUMCVSS 6.8≤ 8.42015-08-17
CVE-2015-5778 [MEDIUM] CVE-2015-5778: CoreMedia Playback in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to exec CoreMedia Playback in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-5777.
nvd
CVE-2015-5777P4MEDIUMCVSS 6.8≤ 8.42015-08-17
CVE-2015-5777 [MEDIUM] CWE-119 CVE-2015-5777: CoreMedia Playback in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to exec CoreMedia Playback in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-5778.
nvd
CVE-2016-4708P4MEDIUMCVSS 6.5fixed in 10.02016-09-25
CVE-2016-4708 [MEDIUM] CWE-200 CVE-2016-4708: CFNetwork in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 misparses CFNetwork in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 misparses the Set-Cookie header, which allows remote attackers to obtain sensitive information via a crafted HTTP response.
nvd
CVE-2015-1153P4MEDIUMCVSS 6.8≤ 8.32015-05-08
CVE-2015-1153 [MEDIUM] CVE-2015-1153: WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-1152 and CVE-2015-1154.
nvd
CVE-2015-1152P4MEDIUMCVSS 6.8≤ 8.32015-05-08
CVE-2015-1152 [MEDIUM] CVE-2015-1152: WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-1153 and CVE-2015-1154.
nvd
Apple iOS vulnerabilities | cvebase