Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 137 of 207
CVE-2024-44202P4MEDIUMCVSS 5.3fixed in 18.02024-09-17
CVE-2024-44202 [MEDIUM] CWE-287 CVE-2024-44202: An authentication issue was addressed with improved state management. This issue is fixed in Safari
An authentication issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18. Private Browsing tabs may be accessed without authentication.
nvd
CVE-2024-40852P4MEDIUMCVSS 5.3fixed in 18.02024-09-17
CVE-2024-40852 [MEDIUM] CWE-862 CVE-2024-40852: This issue was addressed by restricting options offered on a locked device. This issue is fixed in i
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18 and iPadOS 18. An attacker may be able to see recent photos without authentication in Assistive Access.
nvd
CVE-2026-20692P4MEDIUMCVSS 5.3fixed in 26.42026-03-25
CVE-2026-20692 [MEDIUM] CVE-2026-20692: A privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS
A privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. "Hide IP Address" and "Block All Remote Content" may not apply to all mail content.
nvd
CVE-2026-20673P4MEDIUMCVSS 5.3fixed in 18.7.52026-02-11
CVE-2026-20673 [MEDIUM] CVE-2026-20673: A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. Turning off "Load remote content in messages” may not apply to all mail previews.
nvd
CVE-2026-20686P4MEDIUMCVSS 5.3fixed in 26.32026-03-25
CVE-2026-20686 [MEDIUM] CWE-20 CVE-2026-20686: This issue was addressed with improved input validation. This issue is fixed in iOS 26.3 and iPadOS
This issue was addressed with improved input validation. This issue is fixed in iOS 26.3 and iPadOS 26.3. An app may be able to access sensitive user data.
nvd
CVE-2020-9894P4MEDIUMCVSS 4.3fixed in 13.62020-10-16
CVE-2020-9894 [MEDIUM] CWE-125 CVE-2020-9894: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.6
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
nvd
CVE-2011-3050P4MEDIUMCVSS 6.8fixed in 6.02012-03-22
CVE-2011-3050 [MEDIUM] CWE-416 CVE-2011-3050: Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome bef
Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 17.0.963.83 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the :first-letter pseudo-element.
nvd
CVE-2011-3032P4MEDIUMCVSS 6.8fixed in 6.02012-03-05
CVE-2011-3032 [MEDIUM] CWE-416 CVE-2011-3032: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of SVG values.
nvd
CVE-2016-4743P4HIGHCVSS 7.1≤ 10.1.12017-02-20
CVE-2016-4743 [HIGH] CWE-119 CVE-2016-4743: An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corruption and ap
nvd
CVE-2015-8242P4MEDIUMCVSS 5.8≤ 9.2.12015-12-15
CVE-2015-8242 [MEDIUM] CWE-119 CVE-2015-8242: The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.
The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
nvd
CVE-2016-4773P4HIGHCVSS 7.1fixed in 10.02016-09-25
CVE-2016-4773 [HIGH] CWE-125 CVE-2016-4773: The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows at
The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to obtain sensitive memory-layout information or cause a denial of service (out-of-bounds read) via a crafted app, a different vulnerability than CVE-2016-4774 and CVE-2016-4776.
nvd
CVE-2016-4776P4HIGHCVSS 7.1fixed in 10.02016-09-25
CVE-2016-4776 [HIGH] CVE-2016-4776: The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows at
The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to obtain sensitive memory-layout information or cause a denial of service (out-of-bounds read) via a crafted app, a different vulnerability than CVE-2016-4773 and CVE-2016-4774.
nvd
CVE-2016-4774P4HIGHCVSS 7.1fixed in 10.02016-09-25
CVE-2016-4774 [HIGH] CVE-2016-4774: The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows at
The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to obtain sensitive memory-layout information or cause a denial of service (out-of-bounds read) via a crafted app, a different vulnerability than CVE-2016-4773 and CVE-2016-4776.
nvd
CVE-2011-3041P4MEDIUMCVSS 6.8fixed in 6.02012-03-05
CVE-2011-3041 [MEDIUM] CWE-416 CVE-2011-3041: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of class attributes.
nvd
CVE-2011-1449P4MEDIUMCVSS 6.8fixed in 5.02011-05-03
CVE-2011-1449 [MEDIUM] CWE-416 CVE-2011-1449: Use-after-free vulnerability in the WebSockets implementation in Google Chrome before 11.0.696.57 al
Use-after-free vulnerability in the WebSockets implementation in Google Chrome before 11.0.696.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-2790P4MEDIUMCVSS 6.8fixed in 5.02011-08-03
CVE-2011-2790 [MEDIUM] CWE-416 CVE-2011-2790: Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving floating styles.
nvd
CVE-2011-3016P4MEDIUMCVSS 6.8fixed in 6.02012-02-16
CVE-2011-3016 [MEDIUM] CWE-416 CVE-2011-3016: Use-after-free vulnerability in Google Chrome before 17.0.963.56 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving counter nodes, related to a "read-after-free" issue.
nvd
CVE-2013-0968P4MEDIUMCVSS 6.8≤ 6.0.2v6.0+1 more2013-01-29
CVE-2013-0968 [MEDIUM] CWE-119 CVE-2013-0968: WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause
WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.
nvd
CVE-2011-2788P4MEDIUMCVSS 6.8fixed in 5.02011-08-03
CVE-2011-2788 [MEDIUM] CWE-120 CVE-2011-2788: Buffer overflow in the inspector serialization functionality in Google Chrome before 13.0.782.107 al
Buffer overflow in the inspector serialization functionality in Google Chrome before 13.0.782.107 allows user-assisted remote attackers to have an unspecified impact via unknown vectors.
nvd
CVE-2015-3800P4HIGHCVSS 7.2≤ 8.42015-08-17
CVE-2015-3800 [HIGH] CWE-119 CVE-2015-3800: The DiskImages component in Apple iOS before 8.4.1 and OS X before 10.10.5 allows local users to gai
The DiskImages component in Apple iOS before 8.4.1 and OS X before 10.10.5 allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via a malformed DMG image.
nvd