Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 127 of 207
CVE-2026-20641P4HIGHCVSS 7.1fixed in 18.7.5≥ 26.0, < 26.32026-02-11
CVE-2026-20641 [HIGH] CWE-200 CVE-2026-20641: A privacy issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.
A privacy issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to identify what other apps a user has installed.
nvd
CVE-2026-20628P4HIGHCVSS 7.1fixed in 18.7.5≥ 26.0, < 26.32026-02-11
CVE-2026-20628 [HIGH] CWE-284 CVE-2026-20628: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.5 an
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to break out of its sandbox.
nvd
CVE-2018-4271P4MEDIUMCVSS 6.5fixed in 11.4.12019-04-03
CVE-2018-4271 [MEDIUM] CWE-119 CVE-2018-4271: Multiple memory corruption issues were addressed with improved input validation. This issue affected
Multiple memory corruption issues were addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvd
CVE-2024-23259P4MEDIUMCVSS 6.5fixed in 16.7.6≥ 17.0, < 17.42024-03-08
CVE-2024-23259 [MEDIUM] CWE-400 CVE-2024-23259: The issue was addressed with improved checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, i
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Processing web content may lead to a denial-of-service.
nvd
CVE-2022-22658P4MEDIUMCVSS 6.5fixed in 16.0.32022-11-01
CVE-2022-22658 [MEDIUM] CWE-20 CVE-2022-22658: An input validation issue was addressed with improved input validation. This issue is fixed in iOS 1
An input validation issue was addressed with improved input validation. This issue is fixed in iOS 16.0.3. Processing a maliciously crafted email message may lead to a denial-of-service.
nvd
CVE-2024-54526P4MEDIUMCVSS 5.5fixed in 18.22024-12-12
CVE-2024-54526 [MEDIUM] CVE-2024-54526: The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS
The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, watchOS 11.2. A malicious app may be able to access private information.
nvd
CVE-2017-2475P4MEDIUMCVSS 6.1fixed in 10.32017-04-02
CVE-2017-2475 [MEDIUM] CWE-79 CVE-2017-2475: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via crafted use of frames on a web site.
nvd
CVE-2020-3841P4MEDIUMCVSS 6.5fixed in 13.3.12020-02-27
CVE-2020-3841 [MEDIUM] CWE-319 CVE-2020-3841: The issue was addressed with improved UI handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3
The issue was addressed with improved UI handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, Safari 13.0.5. A local user may unknowingly send a password unencrypted over the network.
nvd
CVE-2020-3867P4MEDIUMCVSS 6.1fixed in 13.3.12020-02-27
CVE-2020-3867 [MEDIUM] CWE-79 CVE-2020-3867: A logic issue was addressed with improved state management. This issue is fixed in iOS 13.3.1 and iP
A logic issue was addressed with improved state management. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
CVE-2017-7088P4MEDIUMCVSS 5.9≤ 10.3.32017-10-23
CVE-2017-7088 [MEDIUM] CWE-275 CVE-2017-7088: An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Exchange ActiveSync" component. It allows remote attackers to erase a device in opportunistic circumstances by hijacking a cleartext AutoDiscover V1 session during the setup of an Exchange account.
nvd
CVE-2021-1825P4MEDIUMCVSS 6.1fixed in 14.52021-09-08
CVE-2021-1825 [MEDIUM] CWE-79 CVE-2021-1825: An input validation issue was addressed with improved input validation. This issue is fixed in iTune
An input validation issue was addressed with improved input validation. This issue is fixed in iTunes 12.11.3 for Windows, iCloud for Windows 12.3, macOS Big Sur 11.3, Safari 14.1, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may lead to a cross site scripting attack.
nvd
CVE-2026-43804P4MEDIUMCVSS 6.5fixed in 26.62026-07-27
CVE-2026-43804 [MEDIUM] CWE-400 CVE-2026-43804: This issue was addressed through improved state management. This issue is fixed in Safari 26.6, iOS
This issue was addressed through improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6. Visiting a website may lead to an app denial-of-service.
nvd
CVE-2021-30890P4MEDIUMCVSS 6.1fixed in 15.12021-08-24
CVE-2021-30890 [MEDIUM] CWE-79 CVE-2021-30890: A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1, iOS 15.1 and iPadOS 15.1, watchOS 8.1, tvOS 15.1. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
CVE-2018-4266P4MEDIUMCVSS 5.9fixed in 11.4.12019-04-03
CVE-2018-4266 [MEDIUM] CWE-362 CVE-2018-4266: A race condition was addressed with additional validation. This issue affected versions prior toiVer
A race condition was addressed with additional validation. This issue affected versions prior toiVersions prior to: OS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvd
CVE-2019-8658P4MEDIUMCVSS 6.1fixed in 12.42019-12-18
CVE-2019-8658 [MEDIUM] CWE-79 CVE-2019-8658: A logic issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS M
A logic issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
CVE-2017-2549P4MEDIUMCVSS 6.1≤ 10.3.12017-05-22
CVE-2017-2549 [MEDIUM] CWE-79 CVE-2017-2549: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with frame loading.
nvd
CVE-2020-9925P4MEDIUMCVSS 6.1fixed in 13.62020-10-16
CVE-2020-9925 [MEDIUM] CWE-79 CVE-2020-9925: A logic issue was addressed with improved state management. This issue is fixed in iOS 13.6 and iPad
A logic issue was addressed with improved state management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
CVE-2024-40785P4MEDIUMCVSS 6.1fixed in 16.7.9≥ 17.0, < 17.62024-07-29
CVE-2024-40785 [MEDIUM] CWE-79 CVE-2024-40785: This issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 16.7.9 and iP
This issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to a cross site scripting attack.
nvd
CVE-2024-40857P4MEDIUMCVSS 6.1fixed in 18.02024-09-17
CVE-2024-40857 [MEDIUM] CWE-79 CVE-2024-40857: This issue was addressed through improved state management. This issue is fixed in Safari 18, iOS 18
This issue was addressed through improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
CVE-2017-13860P4MEDIUMCVSS 5.9fixed in 11.22017-12-25
CVE-2017-13860 [MEDIUM] CVE-2017-13860: An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. The issue involves the "Mail Drafts" component. It allows man-in-the-middle attackers to read e-mail content by leveraging mishandling of S/MIME credential encryption.
nvd