cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 130 of 207
CVE-2018-4374P4MEDIUMCVSS 6.1fixed in 12.12019-04-03
CVE-2018-4374 [MEDIUM] CWE-79 CVE-2018-4374: A logic issue was addressed with improved validation. This issue affected versions prior to iOS 12.1 A logic issue was addressed with improved validation. This issue affected versions prior to iOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
nvd
CVE-2022-22588P4MEDIUMCVSS 5.5fixed in 15.2.12022-03-18
CVE-2022-22588 [MEDIUM] CWE-20 CVE-2022-22588: A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 15.2.1 and iPadOS 15.2.1. Processing a maliciously crafted HomeKit accessory name may cause a denial of service.
nvd
CVE-2016-4690P4MEDIUMCVSS 6.8≤ 10.1.12017-02-20
CVE-2016-4690 [MEDIUM] CWE-20 CVE-2016-4690: An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves t An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Image Capture" component, which allows attackers to execute arbitrary code via a crafted USB HID device.
nvd
CVE-2019-8554P4MEDIUMCVSS 6.5fixed in 12.22019-12-18
CVE-2019-8554 [MEDIUM] CVE-2019-8554: A permissions issue existed in the handling of motion and orientation data. This issue was addressed A permissions issue existed in the handling of motion and orientation data. This issue was addressed with improved restrictions. This issue is fixed in iOS 12.2. A website may be able to access sensor information without user consent.
nvd
CVE-2025-31228P4MEDIUMCVSS 6.8fixed in 18.52025-05-12
CVE-2025-31228 [MEDIUM] CWE-287 CVE-2025-31228: The issue was addressed with improved authentication. This issue is fixed in iOS 18.5 and iPadOS 18. The issue was addressed with improved authentication. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An attacker with physical access to a device may be able to access notes from the lock screen.
nvd
CVE-2019-8626P4MEDIUMCVSS 6.5fixed in 12.32019-12-18
CVE-2019-8626 [MEDIUM] CWE-20 CVE-2019-8626: An input validation issue was addressed with improved input validation. This issue is fixed in iOS 1 An input validation issue was addressed with improved input validation. This issue is fixed in iOS 12.3, watchOS 5.2.1. Processing a maliciously crafted message may lead to a denial of service.
nvd
CVE-2018-4362P4MEDIUMCVSS 6.5fixed in 12.02019-04-03
CVE-2018-4362 [MEDIUM] CWE-20 CVE-2018-4362: An inconsistent user interface issue was addressed with improved state management. This issue affect An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to Safari 11.1.2, iOS 12.
nvd
CVE-2023-42956P4MEDIUMCVSS 6.5fixed in 17.22024-03-28
CVE-2023-42956 [MEDIUM] CVE-2023-42956: The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, iOS 17.2 The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2. Processing web content may lead to a denial-of-service.
nvd
CVE-2023-40441P4MEDIUMCVSS 6.5fixed in 17.02023-09-27
CVE-2023-40441 [MEDIUM] CWE-400 CVE-2023-40441: A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may lead to a denial-of-service.
nvd
CVE-2021-30870P4MEDIUMCVSS 6.5fixed in 15.02021-08-24
CVE-2021-30870 [MEDIUM] CVE-2021-30870: A logic issue existed in the handling of document loads. This issue was addressed with improved stat A logic issue existed in the handling of document loads. This issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15. Previewing an html file attached to a note may unexpectedly contact remote servers.
nvd
CVE-2019-8664P4MEDIUMCVSS 6.5fixed in 12.32020-10-27
CVE-2019-8664 [MEDIUM] CWE-20 CVE-2019-8664: An input validation issue was addressed with improved input validation. This issue is fixed in iOS 1 An input validation issue was addressed with improved input validation. This issue is fixed in iOS 12.3, watchOS 5.2.1. Processing a maliciously crafted message may lead to a denial of service.
nvd
CVE-2018-4260P4MEDIUMCVSS 6.5fixed in 11.4.12019-04-03
CVE-2018-4260 [MEDIUM] CWE-20 CVE-2018-4260: An inconsistent user interface issue was addressed with improved state management. This issue affect An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to iOS 11.4.1, Safari 11.1.2.
nvd
CVE-2017-13891P4MEDIUMCVSS 6.5fixed in 11.22019-01-11
CVE-2017-13891 [MEDIUM] CWE-20 CVE-2017-13891: In iOS before 11.2, an inconsistent user interface issue was addressed through improved state manage In iOS before 11.2, an inconsistent user interface issue was addressed through improved state management.
nvd
CVE-2024-54658P4MEDIUMCVSS 6.5fixed in 17.42025-02-10
CVE-2024-54658 [MEDIUM] CWE-400 CVE-2024-54658: The issue was addressed with improved memory handling. This issue is fixed in Safari 17.4, iOS 17.4 The issue was addressed with improved memory handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing web content may lead to a denial-of-service.
nvd
CVE-2025-31210P4MEDIUMCVSS 6.5fixed in 18.52025-05-12
CVE-2025-31210 [MEDIUM] CWE-400 CVE-2025-31210: The issue was addressed with improved UI. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17 The issue was addressed with improved UI. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. Processing web content may lead to a denial-of-service.
nvd
CVE-2023-23528P4MEDIUMCVSS 6.5fixed in 16.42023-05-08
CVE-2023-23528 [MEDIUM] CWE-125 CVE-2023-23528: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in tvOS 16.4, An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in tvOS 16.4, iOS 16.4 and iPadOS 16.4. Processing a maliciously crafted Bluetooth packet may result in disclosure of process memory.
nvd
CVE-2019-8813P4MEDIUMCVSS 6.1fixed in 13.22019-12-18
CVE-2019-8813 [MEDIUM] CWE-79 CVE-2019-8813: A logic issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPad A logic issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
CVE-2022-42799P4MEDIUMCVSS 6.1fixed in 16.12022-11-01
CVE-2022-42799 [MEDIUM] CWE-1021 CVE-2022-42799: The issue was addressed with improved UI handling. This issue is fixed in tvOS 16.1, macOS Ventura 1 The issue was addressed with improved UI handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Visiting a malicious website may lead to user interface spoofing.
nvd
CVE-2021-1884P4MEDIUMCVSS 5.9fixed in 14.52021-09-08
CVE-2021-1884 [MEDIUM] CWE-362 CVE-2021-1884: A race condition was addressed with improved locking. This issue is fixed in Security Update 2021-00 A race condition was addressed with improved locking. This issue is fixed in Security Update 2021-004 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, Security Update 2021-003 Catalina, tvOS 14.5, macOS Big Sur 11.3. A remote attacker may be able to cause a denial of service.
nvd
CVE-2026-20680P4MEDIUMCVSS 6.5fixed in 18.7.5≥ 26.0, < 26.32026-02-11
CVE-2026-20680 [MEDIUM] CWE-200 CVE-2026-20680: The issue was addressed with additional restrictions on the observability of app states. This issue The issue was addressed with additional restrictions on the observability of app states. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. A sandboxed app may be able to access sensitive user data.
nvd
Apple iOS vulnerabilities | cvebase