cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 105 of 207
CVE-2016-7667P4HIGHCVSS 7.5≤ 10.1.12017-02-20
CVE-2016-7667 [HIGH] CWE-20 CVE-2016-7667: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service via a crafted string.
nvd
CVE-2016-4627P4HIGHCVSS 7.8fixed in 9.3.32016-07-22
CVE-2016-4627 [HIGH] CWE-476 CVE-2016-4627: IOAcceleratorFamily in Apple iOS before 9.3.3, tvOS before 9.2.2, and watchOS before 2.2.2 allows lo IOAcceleratorFamily in Apple iOS before 9.3.3, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors.
nvd
CVE-2015-6989P4MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-6989 [MEDIUM] CWE-119 CVE-2015-6989: Grand Central Dispatch in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows Grand Central Dispatch in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted package that is mishandled during dispatch calls.
nvd
CVE-2014-8840P4MEDIUMCVSS 6.8≤ 8.1.22015-01-30
CVE-2014-8840 [MEDIUM] CWE-310 CVE-2014-8840: The iTunes Store component in Apple iOS before 8.1.3 allows remote attackers to bypass a Safari sand The iTunes Store component in Apple iOS before 8.1.3 allows remote attackers to bypass a Safari sandbox protection mechanism by leveraging redirection of an SSL URL to the iTunes Store.
nvd
CVE-2011-3430P4CRITICALCVSS 9.3v3.0v3.1+17 more2011-10-14
CVE-2011-3430 [CRITICAL] CVE-2011-3430: The Settings component in Apple iOS before 5, when a configuration profile is used for a locale othe The Settings component in Apple iOS before 5, when a configuration profile is used for a locale other than English, does not properly implement localization, which makes it easier for attackers to have an unspecified impact by leveraging incorrect configuration display.
nvd
CVE-2019-8570P4MEDIUMCVSS 6.5fixed in 12.1.32020-10-27
CVE-2019-8570 [MEDIUM] CVE-2019-8570: A logic issue was addressed with improved state management. This issue is fixed in iOS 12.1.3, iClou A logic issue was addressed with improved state management. This issue is fixed in iOS 12.1.3, iCloud for Windows 7.10, iTunes 12.9.3 for Windows, Safari 12.0.3, tvOS 12.1.2. Processing maliciously crafted web content may disclose sensitive user information.
nvd
CVE-2016-4718P4MEDIUMCVSS 6.5fixed in 10.02016-09-25
CVE-2016-4718 [MEDIUM] CWE-119 CVE-2016-4718: Buffer overflow in FontParser in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS Buffer overflow in FontParser in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to obtain sensitive information from process memory via a crafted font file.
nvd
CVE-2018-4157P4HIGHCVSS 7.0fixed in 11.32018-04-03
CVE-2018-4157 [HIGH] CWE-362 CVE-2018-4157: An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "Quick Look" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2018-4166P4HIGHCVSS 7.0fixed in 11.32018-04-03
CVE-2018-4166 [HIGH] CWE-362 CVE-2018-4166: An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "NSURLSession" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2018-4155P4HIGHCVSS 7.0fixed in 11.32018-04-03
CVE-2018-4155 [HIGH] CWE-362 CVE-2018-4155: An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "CoreFoundation" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2015-1095P4HIGHCVSS 7.2≤ 8.22015-04-10
CVE-2015-1095 [HIGH] CVE-2015-1095: IOHIDFamily in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows physi IOHIDFamily in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HID device.
nvd
CVE-2021-30996P4HIGHCVSS 7.0fixed in 15.22021-08-24
CVE-2021-30996 [HIGH] CWE-362 CVE-2021-30996: A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 1 A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 12.1, iOS 15.2 and iPadOS 15.2. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2026-28941P4HIGHCVSS 7.1fixed in 18.7.92026-05-11
CVE-2026-28941 [HIGH] CWE-119 CVE-2026-28941: The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, m The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Tahoe 26.5. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.
nvd
CVE-2021-30923P4HIGHCVSS 7.0fixed in 15.12021-08-24
CVE-2021-30923 [HIGH] CWE-362 CVE-2021-30923: A race condition was addressed with improved locking. This issue is fixed in macOS Monterey 12.0.1. A race condition was addressed with improved locking. This issue is fixed in macOS Monterey 12.0.1. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2022-22638P4MEDIUMCVSS 6.5fixed in 15.42022-03-18
CVE-2022-22638 [MEDIUM] CWE-476 CVE-2022-22638: A null pointer dereference was addressed with improved validation. This issue is fixed in tvOS 15.4, A null pointer dereference was addressed with improved validation. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, Security Update 2022-003 Catalina, watchOS 8.5, macOS Monterey 12.3. An attacker in a privileged position may be able to perform a denial of service attack.
nvd
CVE-2024-40787P4HIGHCVSS 7.1fixed in 17.62024-07-29
CVE-2024-40787 [HIGH] CVE-2024-40787: This issue was addressed by adding an additional prompt for user consent. This issue is fixed in iOS This issue was addressed by adding an additional prompt for user consent. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, watchOS 10.6. A shortcut may be able to bypass Internet permission requirements.
nvd
CVE-2024-40774P4HIGHCVSS 7.1fixed in 17.62024-07-29
CVE-2024-40774 [HIGH] CVE-2024-40774: A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in iO A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, watchOS 10.6. An app may be able to bypass Privacy preferences.
nvd
CVE-2016-7599P4MEDIUMCVSS 6.5≤ 10.1.12017-02-20
CVE-2016-7599 [MEDIUM] CWE-200 CVE-2016-7599: An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site that uses HTTP
nvd
CVE-2016-7598P4MEDIUMCVSS 6.5≤ 10.1.12017-02-20
CVE-2016-7598 [MEDIUM] CWE-200 CVE-2016-7598: An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information from process memory via a crafted web site.
nvd
CVE-2021-1811P4MEDIUMCVSS 6.5fixed in 14.52021-09-08
CVE-2021-1811 [MEDIUM] CVE-2021-1811: A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.11.3 fo A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.11.3 for Windows, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iCloud for Windows 12.3, macOS Big Sur 11.3, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing a maliciously crafted font may result in the disclosure of process memory.
nvd
Apple iOS vulnerabilities | cvebase