cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 123 of 207
CVE-2011-3056P4MEDIUMCVSS 6.8fixed in 5.1.12012-03-22
CVE-2011-3056 [MEDIUM] CWE-346 CVE-2011-3056: Google Chrome before 17.0.963.83 allows remote attackers to bypass the Same Origin Policy via vector Google Chrome before 17.0.963.83 allows remote attackers to bypass the Same Origin Policy via vectors involving a "magic iframe."
nvd
CVE-2018-4273P4MEDIUMCVSS 6.5fixed in 11.4.12019-04-03
CVE-2018-4273 [MEDIUM] CWE-119 CVE-2018-4273: Multiple memory corruption issues were addressed with improved input validation. This issue affected Multiple memory corruption issues were addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvd
CVE-2018-4270P4MEDIUMCVSS 6.5fixed in 11.4.12019-04-03
CVE-2018-4270 [MEDIUM] CWE-119 CVE-2018-4270: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvd
CVE-2018-4439P4MEDIUMCVSS 6.5fixed in 12.1.12019-04-03
CVE-2018-4439 [MEDIUM] CWE-20 CVE-2018-4439: A logic issue was addressed with improved validation. This issue affected versions prior to iOS 12.1 A logic issue was addressed with improved validation. This issue affected versions prior to iOS 12.1.1, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
nvd
CVE-2024-40799P4HIGHCVSS 7.1fixed in 16.7.9≥ 17.0, < 17.62024-07-29
CVE-2024-40799 [HIGH] CWE-125 CVE-2024-40799: An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing a maliciously crafted file may lead to unexpected app termination.
nvd
CVE-2023-32357P4HIGHCVSS 7.1fixed in 16.52023-06-23
CVE-2023-32357 [HIGH] CWE-125 CVE-2023-32357: An authorization issue was addressed with improved state management. This issue is fixed in watchOS An authorization issue was addressed with improved state management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. An app may be able to retain access to system configuration files even after its permission is revoked.
nvd
CVE-2016-4758P4MEDIUMCVSS 6.5≤ 9.3.52016-09-25
CVE-2016-4758 [MEDIUM] CWE-200 CVE-2016-4758: WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not proper WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly restrict access to the location variable, which allows remote attackers to obtain sensitive information via a crafted web site.
nvd
CVE-2026-64725P4HIGHCVSS 7.1fixed in 26.62026-07-27
CVE-2026-64725 [HIGH] CWE-787 CVE-2026-64725: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause a denial-of-service.
nvd
CVE-2021-30796P4MEDIUMCVSS 6.5fixed in 14.72021-09-08
CVE-2021-30796 [MEDIUM] CVE-2021-30796: A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. Processing a maliciously crafted image may lead to a denial of service.
nvd
CVE-2018-4368P4MEDIUMCVSS 6.5fixed in 12.12019-04-03
CVE-2018-4368 [MEDIUM] CWE-20 CVE-2018-4368: A denial of service issue was addressed with improved validation. This issue affected versions prior A denial of service issue was addressed with improved validation. This issue affected versions prior to iOS 12.1, macOS Mojave 10.14.1, tvOS 12.1, watchOS 5.1.
nvd
CVE-2016-1785P4MEDIUMCVSS 6.5≤ 9.2.12016-03-24
CVE-2016-1785 [MEDIUM] CWE-200 CVE-2016-1785: The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles c The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
nvd
CVE-2017-7085P4MEDIUMCVSS 6.5≤ 10.3.32017-10-23
CVE-2017-7085 [MEDIUM] CWE-20 CVE-2017-7085: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar.
nvd
CVE-2015-1086P4MEDIUMCVSS 6.9≤ 8.22015-04-10
CVE-2015-1086 [MEDIUM] CWE-20 CVE-2015-1086: The Audio Drivers subsystem in Apple iOS before 8.3 and Apple TV before 7.2 does not properly valida The Audio Drivers subsystem in Apple iOS before 8.3 and Apple TV before 7.2 does not properly validate IOKit object metadata, which allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2016-7591P4MEDIUMCVSS 6.5≤ 10.1.12017-02-20
CVE-2016-7591 [MEDIUM] CWE-416 CVE-2016-7591: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "IOHIDFamily" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.
nvd
CVE-2017-7011P4MEDIUMCVSS 6.5≤ 10.3.22017-07-20
CVE-2017-7011 [MEDIUM] CWE-20 CVE-2017-7011: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to spoof the address bar via a crafted web site that uses FRAME elements.
nvd
CVE-2021-30659P4MEDIUMCVSS 6.5fixed in 14.52021-09-08
CVE-2021-30659 [MEDIUM] CVE-2021-30659: A validation issue was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14. A validation issue was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, macOS Big Sur 11.3. A malicious application may be able to leak sensitive user information.
nvd
CVE-2017-2517P4MEDIUMCVSS 6.5≤ 10.3.22017-07-20
CVE-2017-2517 [MEDIUM] CWE-20 CVE-2017-2517: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. The issue involves An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site.
nvd
CVE-2018-4444P4MEDIUMCVSS 6.5fixed in 12.1.12020-10-27
CVE-2018-4444 [MEDIUM] CVE-2018-4444: A logic issue was addressed with improved state management. This issue is fixed in Safari 12.0.2, iO A logic issue was addressed with improved state management. This issue is fixed in Safari 12.0.2, iOS 12.1.1, tvOS 12.1.1, iTunes 12.9.2 for Windows. Processing maliciously crafted web content may disclose sensitive user information.
nvd
CVE-2024-54497P4MEDIUMCVSS 6.5fixed in 18.22025-01-27
CVE-2024-54497 [MEDIUM] CWE-770 CVE-2024-54497: The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadO The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.4, macOS Sequoia 15.2, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing web content may lead to a denial-of-service.
nvd
CVE-2019-8528P4MEDIUMCVSS 6.7fixed in 12.22020-10-27
CVE-2019-8528 [MEDIUM] CWE-416 CVE-2019-8528: A use after free issue was addressed with improved memory management. This issue is fixed in watchOS A use after free issue was addressed with improved memory management. This issue is fixed in watchOS 5.2, macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, iOS 12.2. An application may be able to execute arbitrary code with kernel privileges.
nvd
Apple iOS vulnerabilities | cvebase