Apple iOS vulnerabilities
3,940 known vulnerabilities affecting apple/iphone_os.
Total CVEs
3,940
CISA KEV
92
actively exploited
Public exploits
248
Exploited in wild
79
Severity breakdown
CRITICAL313HIGH1610MEDIUM1730LOW287
Vulnerabilities
Page 106 of 197
CVE-2019-8546MEDIUMCVSS 5.5fixed in 12.22019-12-18
CVE-2019-8546 [MEDIUM] CVE-2019-8546: An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 12.2,
An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, watchOS 5.2. A local user may be able to view sensitive user information.
nvd
CVE-2019-8760MEDIUMCVSS 6.8fixed in 13.02019-12-18
CVE-2019-8760 [MEDIUM] CWE-287 CVE-2019-8760: This issue was addressed by improving Face ID machine learning models. This issue is fixed in iOS 13
This issue was addressed by improving Face ID machine learning models. This issue is fixed in iOS 13. A 3D model constructed to look like the enrolled user may authenticate via Face ID.
nvd
CVE-2019-8769MEDIUMCVSS 4.3fixed in 13.12019-12-18
CVE-2019-8769 [MEDIUM] CVE-2019-8769: An issue existed in the drawing of web page elements. The issue was addressed with improved logic. T
An issue existed in the drawing of web page elements. The issue was addressed with improved logic. This issue is fixed in iOS 13.1 and iPadOS 13.1, macOS Catalina 10.15. Visiting a maliciously crafted website may reveal browsing history.
nvd
CVE-2019-8521MEDIUMCVSS 5.5fixed in 12.22019-12-18
CVE-2019-8521 [MEDIUM] CVE-2019-8521: This issue was addressed with improved checks. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4
This issue was addressed with improved checks. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4. A malicious application may be able to overwrite arbitrary files.
nvd
CVE-2019-8598MEDIUMCVSS 5.5fixed in 12.32019-12-18
CVE-2019-8598 [MEDIUM] CWE-119 CVE-2019-8598: An input validation issue was addressed with improved input validation. This issue is fixed in iOS 1
An input validation issue was addressed with improved input validation. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. A malicious application may be able to read restricted memory.
nvd
CVE-2019-8793MEDIUMCVSS 5.5fixed in 13.22019-12-18
CVE-2019-8793 [MEDIUM] CVE-2019-8793: A consistency issue existed in deciding when to show the screen recording indicator. The issue was r
A consistency issue existed in deciding when to show the screen recording indicator. The issue was resolved with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2. A local user may be able to record the screen without a visible screen recording indicator.
nvd
CVE-2019-7284MEDIUMCVSS 4.3fixed in 12.22019-12-18
CVE-2019-7284 [MEDIUM] CVE-2019-7284: This issue was addressed with improved checks. This issue is fixed in iOS 12.2. Processing a malicio
This issue was addressed with improved checks. This issue is fixed in iOS 12.2. Processing a maliciously crafted mail message may lead to S/MIME signature spoofing.
nvd
CVE-2019-8615MEDIUMCVSS 6.5fixed in 12.32019-12-18
CVE-2019-8615 [MEDIUM] CWE-125 CVE-2019-8615: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8804MEDIUMCVSS 5.7fixed in 13.22019-12-18
CVE-2019-8804 [MEDIUM] CWE-287 CVE-2019-8804: An inconsistency in Wi-Fi network configuration settings was addressed. This issue is fixed in iOS 1
An inconsistency in Wi-Fi network configuration settings was addressed. This issue is fixed in iOS 13.2 and iPadOS 13.2. An attacker in physical proximity may be able to force a user onto a malicious Wi-Fi network during device setup.
nvd
CVE-2019-8515MEDIUMCVSS 6.5fixed in 12.22019-12-18
CVE-2019-8515 [MEDIUM] CWE-20 CVE-2019-8515: A cross-origin issue existed with the fetch API. This was addressed with improved input validation.
A cross-origin issue existed with the fetch API. This was addressed with improved input validation. This issue is fixed in iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may disclose sensitive user information.
nvd
CVE-2019-8674MEDIUMCVSS 6.1fixed in 13.02019-12-18
CVE-2019-8674 [MEDIUM] CWE-79 CVE-2019-8674: A logic issue was addressed with improved state management. This issue is fixed in iOS 13, Safari 13
A logic issue was addressed with improved state management. This issue is fixed in iOS 13, Safari 13. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
CVE-2019-8690MEDIUMCVSS 6.1PoCfixed in 12.42019-12-18
CVE-2019-8690 [MEDIUM] CWE-79 CVE-2019-8690: A logic issue existed in the handling of document loads. This issue was addressed with improved stat
A logic issue existed in the handling of document loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to universal cross site script
nvd
CVE-2019-8512MEDIUMCVSS 5.7fixed in 12.22019-12-18
CVE-2019-8512 [MEDIUM] CWE-863 CVE-2019-8512: This issue was addressed with improved transparency. This issue is fixed in iOS 12.2. A user may aut
This issue was addressed with improved transparency. This issue is fixed in iOS 12.2. A user may authorize an enterprise administrator to remotely wipe their device without appropriate disclosure.
nvd
CVE-2019-8813MEDIUMCVSS 6.1fixed in 13.22019-12-18
CVE-2019-8813 [MEDIUM] CWE-79 CVE-2019-8813: A logic issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPad
A logic issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
CVE-2019-8510MEDIUMCVSS 5.5fixed in 12.22019-12-18
CVE-2019-8510 [MEDIUM] CWE-125 CVE-2019-8510: An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to determine kernel memory layout.
nvd
CVE-2019-8626MEDIUMCVSS 6.5fixed in 12.32019-12-18
CVE-2019-8626 [MEDIUM] CWE-20 CVE-2019-8626: An input validation issue was addressed with improved input validation. This issue is fixed in iOS 1
An input validation issue was addressed with improved input validation. This issue is fixed in iOS 12.3, watchOS 5.2.1. Processing a maliciously crafted message may lead to a denial of service.
nvd
CVE-2019-8649MEDIUMCVSS 6.1PoCfixed in 12.42019-12-18
CVE-2019-8649 [MEDIUM] CWE-79 CVE-2019-8649: A logic issue existed in the handling of synchronous page loads. This issue was addressed with impro
A logic issue existed in the handling of synchronous page loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to universal cross sit
nvd
CVE-2019-8698LOWCVSS 3.3fixed in 12.42019-12-18
CVE-2019-8698 [LOW] CWE-20 CVE-2019-8698: A validation issue existed in the entitlement verification. This issue was addressed with improved v
A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in iOS 12.4, tvOS 12.4. A malicious application may be able to restrict access to websites.
nvd
CVE-2019-8541LOWCVSS 3.3fixed in 12.22019-12-18
CVE-2019-8541 [LOW] CVE-2019-8541: A privacy issue existed in motion sensor calibration. This issue was addressed with improved motion
A privacy issue existed in motion sensor calibration. This issue was addressed with improved motion sensor processing. This issue is fixed in iOS 12.2, watchOS 5.2. A malicious app may be able to track users between installs.
nvd
CVE-2019-8630LOWCVSS 3.3fixed in 12.32019-12-18
CVE-2019-8630 [LOW] CVE-2019-8630: The issue was addressed with improved UI handling. This issue is fixed in iOS 12.3. The lock screen
The issue was addressed with improved UI handling. This issue is fixed in iOS 12.3. The lock screen may show a locked icon after unlocking.
nvd