cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 126 of 207
CVE-2015-1819P4MEDIUMCVSS 5.0≤ 9.2.12015-08-14
CVE-2015-1819 [MEDIUM] CWE-399 CVE-2015-1819: The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) vi The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
nvd
CVE-2020-9842P4HIGHCVSS 7.1fixed in 13.52020-06-09
CVE-2020-9842 [HIGH] CVE-2020-9842: An entitlement parsing issue was addressed with improved parsing. This issue is fixed in iOS 13.5 an An entitlement parsing issue was addressed with improved parsing. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A malicious application could interact with system processes to access private information and perform privileged actions.
nvd
CVE-2020-9808P4HIGHCVSS 7.1fixed in 13.52020-06-09
CVE-2020-9808 [HIGH] CWE-787 CVE-2020-9808: A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 1 A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. An application may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2020-13630P4HIGHCVSS 7.0fixed in 14.02020-05-27
CVE-2020-13630 [HIGH] CWE-416 CVE-2020-13630: ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snip ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.
nvd
CVE-2016-1858P4MEDIUMCVSS 6.5fixed in 9.3.22016-05-20
CVE-2016-1858 [MEDIUM] CWE-200 CVE-2016-1858: WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, improperly tr WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, improperly tracks taint attributes, which allows remote attackers to obtain sensitive information via a crafted web site.
nvd
CVE-2011-2805P4MEDIUMCVSS 6.8fixed in 5.02011-08-03
CVE-2011-2805 [MEDIUM] CWE-74 CVE-2011-2805: Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy and condu Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy and conduct script injection attacks via unspecified vectors.
nvd
CVE-2015-5843P4HIGHCVSS 7.2≤ 8.4.12015-09-18
CVE-2015-5843 [HIGH] CWE-119 CVE-2015-5843: IOMobileFrameBuffer in Apple iOS before 9 allows local users to gain privileges or cause a denial of IOMobileFrameBuffer in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2015-5848P4HIGHCVSS 7.2≤ 8.4.12015-09-18
CVE-2015-5848 [HIGH] CWE-119 CVE-2015-5848: IOAcceleratorFamily in Apple iOS before 9 allows local users to gain privileges or cause a denial of IOAcceleratorFamily in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2015-5899P4HIGHCVSS 7.2≤ 8.4.12015-09-18
CVE-2015-5899 [HIGH] CWE-119 CVE-2015-5899: libpthread in the kernel in Apple iOS before 9 allows local users to gain privileges or cause a deni libpthread in the kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2015-5847P4HIGHCVSS 7.2≤ 8.4.12015-09-18
CVE-2015-5847 [HIGH] CWE-119 CVE-2015-5847: The Disk Images component in Apple iOS before 9 allows local users to gain privileges or cause a den The Disk Images component in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2017-7038P4MEDIUMCVSS 6.1fixed in 10.3.32017-07-20
CVE-2017-7038 [MEDIUM] CWE-79 CVE-2017-7038: A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safar A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component.
nvd
CVE-2026-20687P4HIGHCVSS 7.1fixed in 18.7.7≥ 26.0, < 26.42026-03-25
CVE-2026-20687 [HIGH] CWE-416 CVE-2026-20687: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18. A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Tahoe 26.4, tvOS 26.4, watchOS 26.4. An app may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2024-44252P4HIGHCVSS 7.1fixed in 17.7.1≥ 18.0, < 18.12024-10-28
CVE-2024-44252 [HIGH] CVE-2024-44252: A logic issue was addressed with improved file handling. This issue is fixed in iOS 17.7.1 and iPadO A logic issue was addressed with improved file handling. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, tvOS 18.1, visionOS 2.1. Restoring a maliciously crafted backup file may lead to modification of protected system files.
nvd
CVE-2018-4428P4HIGHCVSS 7.1fixed in 12.1.12020-10-27
CVE-2018-4428 [HIGH] CVE-2018-4428: A lock screen issue allowed access to the share function on a locked device. This issue was addresse A lock screen issue allowed access to the share function on a locked device. This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 12.1.1. A local attacker may be able to share items from the lock screen.
nvd
CVE-2025-43224P4HIGHCVSS 7.1fixed in 18.62025-07-30
CVE-2025-43224 [HIGH] CWE-787 CVE-2025-43224: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
nvd
CVE-2025-24257P4HIGHCVSS 7.1fixed in 18.42025-03-31
CVE-2025-24257 [HIGH] CWE-787 CVE-2025-24257: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iO An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. An app may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2025-43338P4HIGHCVSS 7.1fixed in 26.02025-11-04
CVE-2025-43338 [HIGH] CWE-79 CVE-2025-43338: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26 and iPadOS 26, macOS Sonoma 14.8.2, macOS Sonoma 14.8.4, macOS Tahoe 26. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
nvd
CVE-2025-43221P4HIGHCVSS 7.1fixed in 18.62025-07-30
CVE-2025-43221 [HIGH] CWE-125 CVE-2025-43221: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
nvd
CVE-2014-4494P4MEDIUMCVSS 6.8≤ 8.1.22015-01-30
CVE-2014-4494 [MEDIUM] CWE-20 CVE-2014-4494: Springboard in Apple iOS before 8.1.3 does not properly validate signatures when determining whether Springboard in Apple iOS before 8.1.3 does not properly validate signatures when determining whether to solicit an app trust decision from the user, which allows attackers to bypass intended first-launch restrictions by leveraging access to an enterprise distribution certificate for signing a crafted app.
nvd
CVE-2018-4409P4MEDIUMCVSS 6.5fixed in 12.12019-04-03
CVE-2018-4409 [MEDIUM] CWE-400 CVE-2018-4409: A resource exhaustion issue was addressed with improved input validation. This issue affected versio A resource exhaustion issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1, tvOS 12.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
nvd
Apple iOS vulnerabilities | cvebase