Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 124 of 207
CVE-2024-23271P4MEDIUMCVSS 6.5fixed in 17.32024-04-24
CVE-2024-23271 [MEDIUM] CWE-284 CVE-2024-23271: A logic issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 17.3 and i
A logic issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. A malicious website may cause unexpected cross-origin behavior.
nvd
CVE-2025-24192P4MEDIUMCVSS 6.5fixed in 18.42025-03-31
CVE-2025-24192 [MEDIUM] CVE-2025-24192: A script imports issue was addressed with improved isolation. This issue is fixed in Safari 18.4, iO
A script imports issue was addressed with improved isolation. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4. Visiting a website may leak sensitive data.
nvd
CVE-2022-32784P4MEDIUMCVSS 6.5fixed in 15.52023-02-27
CVE-2022-32784 [MEDIUM] CWE-200 CVE-2022-32784: The issue was addressed with improved UI handling. This issue is fixed in Safari 15.6, iOS 15.6 and
The issue was addressed with improved UI handling. This issue is fixed in Safari 15.6, iOS 15.6 and iPadOS 15.6. Visiting a maliciously crafted website may leak sensitive data.
nvd
CVE-2026-43663P4MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-43663 [MEDIUM] CWE-119 CVE-2026-43663: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-39872P4MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-39872 [MEDIUM] CWE-119 CVE-2026-39872: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2018-4202P4MEDIUMCVSS 5.9fixed in 11.42018-06-08
CVE-2018-4202 [MEDIUM] CWE-20 CVE-2018-4202: An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. The issue involves the "iBooks" component. It allows man-in-the-middle attackers to spoof a password prompt.
nvd
CVE-2016-4642P4MEDIUMCVSS 5.9fixed in 9.3.32019-01-11
CVE-2016-4642 [MEDIUM] CWE-254 CVE-2016-4642: In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016
In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, proxy authentication incorrectly reported HTTP proxies received credentials securely. This issue was addressed through improved warnings.
nvd
CVE-2018-4086P4MEDIUMCVSS 5.9fixed in 11.2.52018-04-03
CVE-2018-4086 [MEDIUM] CWE-295 CVE-2018-4086: An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "Security" component. It allows remote attackers to spoof certificate validation via crafted name constraints.
nvd
CVE-2024-54492P4MEDIUMCVSS 5.9fixed in 18.22024-12-12
CVE-2024-54492 [MEDIUM] CVE-2024-54492: This issue was addressed by using HTTPS when sending information over the network. This issue is fix
This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, visionOS 2.2. An attacker in a privileged network position may be able to alter network traffic.
nvd
CVE-2014-4369P4HIGHCVSS 7.8≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4369 [HIGH] CVE-2014-4369: The IOAcceleratorFamily API implementation in Apple iOS before 8 and Apple TV before 7 allows attack
The IOAcceleratorFamily API implementation in Apple iOS before 8 and Apple TV before 7 allows attackers to cause a denial of service (NULL pointer dereference and device crash) via an application that uses crafted arguments.
nvd
CVE-2011-1121P4HIGHCVSS 7.5fixed in 5.02011-03-01
CVE-2011-1121 [HIGH] CWE-190 CVE-2011-1121: Integer overflow in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of se
Integer overflow in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a TEXTAREA element.
nvd
CVE-2014-4374P4MEDIUMCVSS 5.0≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4374 [MEDIUM] CVE-2014-4374: NSXMLParser in Foundation in Apple iOS before 8 allows attackers to read arbitrary files via XML dat
NSXMLParser in Foundation in Apple iOS before 8 allows attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
nvd
CVE-2011-1188P4HIGHCVSS 7.5fixed in 5.02011-03-11
CVE-2011-1188 [HIGH] CVE-2011-1188: Google Chrome before 10.0.648.127 does not properly handle counter nodes, which allows remote attack
Google Chrome before 10.0.648.127 does not properly handle counter nodes, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-2827P4HIGHCVSS 7.5fixed in 5.02011-08-29
CVE-2011-2827 [HIGH] CWE-416 CVE-2011-2827: Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to text searching.
nvd
CVE-2023-42898P4MEDIUMCVSS 5.5≥ 17.0, < 17.22023-12-12
CVE-2023-42898 [MEDIUM] CVE-2023-42898: The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2, wat
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2, watchOS 10.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2. Processing an image may lead to arbitrary code execution.
nvd
CVE-2012-2824P4HIGHCVSS 7.5≤ 6.0.2v6.0+1 more2012-06-27
CVE-2012-2824 [HIGH] CWE-399 CVE-2012-2824: Use-after-free vulnerability in Google Chrome before 20.0.1132.43 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG painting.
nvd
CVE-2014-4474P4MEDIUMCVSS 6.8≤ 8.1.22014-12-10
CVE-2014-4474 [MEDIUM] CWE-399 CVE-2014-4474: WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote
WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-12-2-1.
nvd
CVE-2014-4473P4MEDIUMCVSS 6.8≤ 8.1.22014-12-10
CVE-2014-4473 [MEDIUM] CWE-399 CVE-2014-4473: WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote
WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-12-2-1.
nvd
CVE-2014-4471P4MEDIUMCVSS 6.8≤ 8.1.22014-12-10
CVE-2014-4471 [MEDIUM] CWE-399 CVE-2014-4471: WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote
WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-12-2-1.
nvd
CVE-2009-3273P4HIGHCVSS 7.5v1.0v1.0.0+19 more2009-09-21
CVE-2009-3273 [HIGH] CWE-310 CVE-2009-3273: iPhone Mail in Apple iPhone OS, and iPhone OS for iPod touch, does not validate X.509 certificates,
iPhone Mail in Apple iPhone OS, and iPhone OS for iPod touch, does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL e-mail servers via a crafted certificate.
nvd