Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 128 of 207
CVE-2024-23277P4MEDIUMCVSS 5.9≥ 17.0, < 17.42024-03-08
CVE-2024-23277 [MEDIUM] CVE-2024-23277: The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS
The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An attacker in a privileged network position may be able to inject keystrokes by spoofing a keyboard.
nvd
CVE-2011-0983P4HIGHCVSS 7.5fixed in 5.02011-02-10
CVE-2011-0983 [HIGH] CWE-20 CVE-2011-0983: Google Chrome before 9.0.597.94 does not properly handle anonymous blocks, which allows remote attac
Google Chrome before 9.0.597.94 does not properly handle anonymous blocks, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-0981P4HIGHCVSS 7.5fixed in 5.02011-02-10
CVE-2011-0981 [HIGH] CWE-20 CVE-2011-0981: Google Chrome before 9.0.597.94 does not properly perform event handling for animations, which allow
Google Chrome before 9.0.597.94 does not properly perform event handling for animations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-2821P4HIGHCVSS 7.5fixed in 6.02011-08-29
CVE-2011-2821 [HIGH] CWE-415 CVE-2011-2821: Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.215, allows remote at
Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted XPath expression.
nvd
CVE-2015-3801P4MEDIUMCVSS 5.0≤ 8.4.12015-09-18
CVE-2015-3801 [MEDIUM] CWE-264 CVE-2015-3801: The document.cookie API implementation in the CFNetwork Cookies subsystem in WebKit in Apple iOS bef
The document.cookie API implementation in the CFNetwork Cookies subsystem in WebKit in Apple iOS before 9 allows remote attackers to bypass an intended single-cookie restriction via unspecified vectors.
nvd
CVE-2020-9916P4MEDIUMCVSS 5.3fixed in 13.62020-10-16
CVE-2020-9916 [MEDIUM] CVE-2020-9916: A URL Unicode encoding issue was addressed with improved state management. This issue is fixed in iO
A URL Unicode encoding issue was addressed with improved state management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A malicious attacker may be able to conceal the destination of a URL.
nvd
CVE-2011-1203P4HIGHCVSS 7.5fixed in 5.02011-03-11
CVE-2011-1203 [HIGH] CVE-2011-1203: Google Chrome before 10.0.648.127 does not properly handle SVG cursors, which allows remote attacker
Google Chrome before 10.0.648.127 does not properly handle SVG cursors, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1109P4HIGHCVSS 7.5fixed in 5.02011-03-01
CVE-2011-1109 [HIGH] CWE-20 CVE-2011-1109: Google Chrome before 9.0.597.107 does not properly process nodes in Cascading Style Sheets (CSS) sty
Google Chrome before 9.0.597.107 does not properly process nodes in Cascading Style Sheets (CSS) stylesheets, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2023-42846P4MEDIUMCVSS 5.3fixed in 16.7.2≥ 17.0, < 17.12023-10-25
CVE-2023-42846 [MEDIUM] CWE-200 CVE-2023-42846: This issue was addressed by removing the vulnerable code. This issue is fixed in watchOS 10.1, iOS 1
This issue was addressed by removing the vulnerable code. This issue is fixed in watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, tvOS 17.1, iOS 17.1 and iPadOS 17.1. A device may be passively tracked by its Wi-Fi MAC address.
nvd
CVE-2015-1065P4MEDIUMCVSS 5.4≤ 8.1.32015-03-12
CVE-2015-1065 [MEDIUM] CWE-119 CVE-2015-1065: Multiple buffer overflows in iCloud Keychain in Apple iOS before 8.2 and Apple OS X through 10.10.2
Multiple buffer overflows in iCloud Keychain in Apple iOS before 8.2 and Apple OS X through 10.10.2 allow man-in-the-middle attackers to execute arbitrary code by modifying the client-server data stream during keychain recovery.
nvd
CVE-2024-27834P4MEDIUMCVSS 5.5fixed in 17.52024-05-14
CVE-2024-27834 [MEDIUM] CWE-277 CVE-2024-27834: The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPa
The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, watchOS 10.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
nvd
CVE-2024-27876P4MEDIUMCVSS 5.5fixed in 17.72024-09-17
CVE-2024-27876 [MEDIUM] CWE-362 CVE-2024-27876: A race condition was addressed with improved locking. This issue is fixed in iOS 17.7 and iPadOS 17.
A race condition was addressed with improved locking. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7, visionOS 2. Unpacking a maliciously crafted archive may allow an attacker to write arbitrary files.
nvd
CVE-2013-5128P4MEDIUMCVSS 6.8≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-5128 [MEDIUM] CWE-119 CVE-2013-5128: WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a
WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.
nvd
CVE-2013-5127P4MEDIUMCVSS 6.8≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-5127 [MEDIUM] CWE-119 CVE-2013-5127: WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a
WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.
nvd
CVE-2013-1042P4MEDIUMCVSS 6.8≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-1042 [MEDIUM] CWE-119 CVE-2013-1042: WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a
WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.
nvd
CVE-2013-1046P4MEDIUMCVSS 6.8≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-1046 [MEDIUM] CWE-119 CVE-2013-1046: WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a
WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.
nvd
CVE-2013-5126P4MEDIUMCVSS 6.8≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-5126 [MEDIUM] CWE-119 CVE-2013-5126: WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a
WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.
nvd
CVE-2013-5125P4MEDIUMCVSS 6.8≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-5125 [MEDIUM] CWE-119 CVE-2013-5125: WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a
WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.
nvd
CVE-2013-1043P4MEDIUMCVSS 6.8≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-1043 [MEDIUM] CWE-119 CVE-2013-1043: WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a
WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.
nvd
CVE-2013-1044P4MEDIUMCVSS 6.8≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-1044 [MEDIUM] CWE-119 CVE-2013-1044: WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a
WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.
nvd