cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 134 of 207
CVE-2024-44204P4MEDIUMCVSS 5.5fixed in 18.0.12024-10-04
CVE-2024-44204 [MEDIUM] CVE-2024-44204: A logic issue was addressed with improved validation. This issue is fixed in iOS 18.0.1 and iPadOS 1 A logic issue was addressed with improved validation. This issue is fixed in iOS 18.0.1 and iPadOS 18.0.1. A user's saved passwords may be read aloud by VoiceOver.
nvd
CVE-2021-30741P4HIGHCVSS 7.1fixed in 14.62021-09-08
CVE-2021-30741 [HIGH] CWE-416 CVE-2021-30741: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14. A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted mail message may lead to unexpected memory modification or application termination.
nvd
CVE-2017-7151P4HIGHCVSS 7.0fixed in 11.22019-04-03
CVE-2017-7151 [HIGH] CWE-362 CVE-2017-7151: A race condition was addressed with additional validation. This issue affected versions prior to iOS A race condition was addressed with additional validation. This issue affected versions prior to iOS 11.2, macOS High Sierra 10.13.2, tvOS 11.2, watchOS 4.2, iTunes 12.7.2 for Windows, macOS High Sierra 10.13.4.
nvd
CVE-2016-1811P4MEDIUMCVSS 6.5fixed in 9.3.22016-05-20
CVE-2016-1811 [MEDIUM] CWE-476 CVE-2016-1811: ImageIO in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 ImageIO in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted image.
nvd
CVE-2013-0981P4HIGHCVSS 7.2≤ 6.1.2v1.0.0+44 more2013-03-20
CVE-2013-0981 [HIGH] CVE-2013-0981: The IOUSBDeviceFamily driver in the USB implementation in the kernel in Apple iOS before 6.1.3 and A The IOUSBDeviceFamily driver in the USB implementation in the kernel in Apple iOS before 6.1.3 and Apple TV before 5.2.1 accesses pipe object pointers that originated in userspace, which allows local users to gain privileges via crafted code.
nvd
CVE-2015-5896P4HIGHCVSS 7.2≤ 8.4.12015-09-18
CVE-2015-5896 [HIGH] CVE-2015-5896: The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5868 and CVE-2015-5903.
nvd
CVE-2015-5868P4HIGHCVSS 7.2≤ 8.4.12015-09-18
CVE-2015-5868 [HIGH] CWE-119 CVE-2015-5868: The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5896 and CVE-2015-5903.
nvd
CVE-2020-3862P4MEDIUMCVSS 6.5fixed in 13.3.12020-02-27
CVE-2020-3862 [MEDIUM] CVE-2020-3862: A denial of service issue was addressed with improved memory handling. This issue is fixed in iOS 13 A denial of service issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. A malicious website may be able to cause a denial of service.
nvd
CVE-2019-8576P4HIGHCVSS 7.1fixed in 12.32019-12-18
CVE-2019-8576 [HIGH] CWE-125 CVE-2019-8576: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.3, An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A local user may be able to cause unexpected system termination or read kernel memory.
nvd
CVE-2024-44245P4HIGHCVSS 7.1≥ 18.0, < 18.22024-12-12
CVE-2024-44245 [HIGH] CWE-787 CVE-2024-44245: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.2 and iPadOS 18 The issue was addressed with improved memory handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, visionOS 2.2. An app may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2023-32420P4HIGHCVSS 7.1fixed in 16.52023-06-23
CVE-2023-32420 [HIGH] CWE-125 CVE-2023-32420: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 16.5 An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. An app may be able to cause unexpected system termination or read kernel memory.
nvd
CVE-2024-27791P4HIGHCVSS 7.1fixed in 16.7.5≥ 17.0, < 17.32024-04-24
CVE-2024-27791 [HIGH] CWE-119 CVE-2024-27791: The issue was addressed with improved checks. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, i The issue was addressed with improved checks. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3. An app may be able to corrupt coprocessor memory.
nvd
CVE-2018-4247P4MEDIUMCVSS 6.5fixed in 11.42018-06-08
CVE-2018-4247 [MEDIUM] CWE-20 CVE-2018-4247: An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. The issue involves the "Safari" component. It allows remote attackers to cause a denial of service (persistent Safari outage) via a crafted web site.
nvd
CVE-2016-1734P4MEDIUMCVSS 6.8≤ 9.2.12016-03-24
CVE-2016-1734 [MEDIUM] CWE-119 CVE-2016-1734: AppleUSBNetworking in Apple iOS before 9.3 and OS X before 10.11.4 allows physically proximate attac AppleUSBNetworking in Apple iOS before 9.3 and OS X before 10.11.4 allows physically proximate attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted USB device.
nvd
CVE-2023-41988P4MEDIUMCVSS 6.8≥ 17.0, < 17.12023-10-25
CVE-2023-41988 [MEDIUM] CWE-200 CVE-2023-41988: This issue was addressed by restricting options offered on a locked device. This issue is fixed in m This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sonoma 14.1, watchOS 10.1, iOS 17.1 and iPadOS 17.1. An attacker with physical access may be able to use Siri to access sensitive user data.
nvd
CVE-2020-9829P4MEDIUMCVSS 6.5fixed in 13.52020-06-09
CVE-2020-9829 [MEDIUM] CWE-20 CVE-2020-9829: A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.5 a A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5. Processing a maliciously crafted text message may lead to application denial of service.
nvd
CVE-2018-4385P4MEDIUMCVSS 6.5fixed in 12.12019-04-03
CVE-2018-4385 [MEDIUM] CWE-20 CVE-2018-4385: A logic issue was addressed with improved state management. This issue affected versions prior to iO A logic issue was addressed with improved state management. This issue affected versions prior to iOS 12.1.
nvd
CVE-2025-43534P4MEDIUMCVSS 6.8fixed in 18.7.7≥ 26.0, < 26.22026-03-25
CVE-2025-43534 [MEDIUM] CWE-284 CVE-2025-43534: A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.7 and A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.2 and iPadOS 26.2. A user with physical access to an iOS device may be able to bypass Activation Lock.
nvd
CVE-2018-4429P4MEDIUMCVSS 6.5fixed in 12.1.12019-04-03
CVE-2018-4429 [MEDIUM] CWE-20 CVE-2018-4429: A spoofing issue existed in the handling of URLs. This issue was addressed with improved input valid A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1.1, watchOS 5.1.2.
nvd
CVE-2023-23512P4MEDIUMCVSS 6.5fixed in 16.32023-02-27
CVE-2023-23512 [MEDIUM] CVE-2023-23512: The issue was addressed with improved handling of caches. This issue is fixed in watchOS 9.3, tvOS 1 The issue was addressed with improved handling of caches. This issue is fixed in watchOS 9.3, tvOS 16.3, macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. Visiting a website may lead to an app denial-of-service.
nvd
Apple iOS vulnerabilities | cvebase