Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 139 of 207
CVE-2018-4377P4MEDIUMCVSS 6.1fixed in 12.12019-04-03
CVE-2018-4377 [MEDIUM] CWE-79 CVE-2018-4377: A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validatio
A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue affected versions prior to iOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
nvd
CVE-2010-1756P4MEDIUMCVSS 5.8fixed in 4.02010-06-22
CVE-2010-1756 [MEDIUM] CVE-2010-1756: The Settings application in Apple iOS before 4 on the iPhone and iPod touch does not properly report
The Settings application in Apple iOS before 4 on the iPhone and iPod touch does not properly report the wireless network that is in use, which might make it easier for remote attackers to trick users into communicating over an unintended network.
nvd
CVE-2019-8674P4MEDIUMCVSS 6.1fixed in 13.02019-12-18
CVE-2019-8674 [MEDIUM] CWE-79 CVE-2019-8674: A logic issue was addressed with improved state management. This issue is fixed in iOS 13, Safari 13
A logic issue was addressed with improved state management. This issue is fixed in iOS 13, Safari 13. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
CVE-2009-2797P4MEDIUMCVSS 5.0fixed in 3.1fixed in 3.1.12009-09-10
CVE-2009-2797 [MEDIUM] CWE-200 CVE-2009-2797: The WebKit component in Safari in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod to
The WebKit component in Safari in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not remove usernames and passwords from URLs sent in Referer headers, which allows remote attackers to obtain sensitive information by reading Referer logs on a web server.
nvd
CVE-2019-6204P4MEDIUMCVSS 6.1fixed in 12.22019-12-18
CVE-2019-6204 [MEDIUM] CWE-79 CVE-2019-6204: A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, Safari 12.1.
A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, Safari 12.1. Enabling the Safari Reader feature on a maliciously crafted webpage may lead to universal cross site scripting.
nvd
CVE-2019-8505P4MEDIUMCVSS 6.1fixed in 12.22019-12-18
CVE-2019-8505 [MEDIUM] CWE-79 CVE-2019-8505: A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, Safari 12.1.
A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, Safari 12.1. Enabling the Safari Reader feature on a maliciously crafted webpage may lead to universal cross site scripting.
nvd
CVE-2013-0957P4MEDIUMCVSS 5.8≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-0957 [MEDIUM] CWE-264 CVE-2013-0957: Data Protection in Apple iOS before 7 allows attackers to bypass intended limits on incorrect passco
Data Protection in Apple iOS before 7 allows attackers to bypass intended limits on incorrect passcode entry, and consequently avoid a configured Erase Data setting, by leveraging the presence of an app in the third-party sandbox.
nvd
CVE-2024-23223P4MEDIUMCVSS 6.2fixed in 17.32024-01-23
CVE-2024-23223 [MEDIUM] CWE-732 CVE-2024-23223: A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 17.3 and i
A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. An app may be able to access sensitive user data.
nvd
CVE-2025-24208P4MEDIUMCVSS 6.1fixed in 18.42025-03-31
CVE-2025-24208 [MEDIUM] CWE-79 CVE-2025-24208: A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 18.4,
A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4. Loading a malicious iframe may lead to a cross-site scripting attack.
nvd
CVE-2021-1883P4MEDIUMCVSS 5.5fixed in 14.52021-09-08
CVE-2021-1883 [MEDIUM] CWE-787 CVE-2021-1883: This issue was addressed with improved checks. This issue is fixed in Security Update 2021-004 Mojav
This issue was addressed with improved checks. This issue is fixed in Security Update 2021-004 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, Security Update 2021-003 Catalina, tvOS 14.5, macOS Big Sur 11.3. Processing maliciously crafted server messages may lead to heap corruption.
nvd
CVE-2026-28866P4MEDIUMCVSS 6.2fixed in 18.7.7≥ 26.0, < 26.42026-03-25
CVE-2026-28866 [MEDIUM] CWE-59 CVE-2026-28866: This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18.7.7 and
This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access sensitive user data.
nvd
CVE-2026-43653P4MEDIUMCVSS 6.2fixed in 18.7.9≥ 26.0, < 26.52026-05-11
CVE-2026-43653 [MEDIUM] CWE-400 CVE-2026-43653: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.8, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5. An attacker on the local network may be able to cause a denial-of-service.
nvd
CVE-2025-24104P4MEDIUMCVSS 5.5fixed in 18.32025-01-27
CVE-2025-24104 [MEDIUM] CWE-59 CVE-2025-24104: This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.3 and iPa
This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4. Restoring a maliciously crafted backup file may lead to modification of protected system files.
nvd
CVE-2016-4746P4MEDIUMCVSS 5.3≤ 9.3.52016-09-18
CVE-2016-4746 [MEDIUM] CWE-200 CVE-2016-4746: The Keyboards component in Apple iOS before 10 does not properly use a cache for auto-correct sugges
The Keyboards component in Apple iOS before 10 does not properly use a cache for auto-correct suggestions, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an unintended correction.
nvd
CVE-2012-0585P4MEDIUMCVSS 5.0fixed in 5.12012-03-08
CVE-2012-0585 [MEDIUM] CWE-264 CVE-2012-0585: The Private Browsing feature in Safari in Apple iOS before 5.1 allows remote attackers to bypass int
The Private Browsing feature in Safari in Apple iOS before 5.1 allows remote attackers to bypass intended privacy settings and insert history entries via JavaScript code that calls the (1) pushState or (2) replaceState method.
nvd
CVE-2019-8512P4MEDIUMCVSS 5.7fixed in 12.22019-12-18
CVE-2019-8512 [MEDIUM] CWE-863 CVE-2019-8512: This issue was addressed with improved transparency. This issue is fixed in iOS 12.2. A user may aut
This issue was addressed with improved transparency. This issue is fixed in iOS 12.2. A user may authorize an enterprise administrator to remotely wipe their device without appropriate disclosure.
nvd
CVE-2016-1730P4MEDIUMCVSS 5.4≤ 9.22016-02-01
CVE-2016-1730 [MEDIUM] CWE-19 CVE-2016-1730: WebSheet in Apple iOS before 9.2.1 allows remote attackers to read or write to cookies by operating
WebSheet in Apple iOS before 9.2.1 allows remote attackers to read or write to cookies by operating a crafted captive portal.
nvd
CVE-2021-1760P4MEDIUMCVSS 5.5fixed in 14.42021-04-02
CVE-2021-1760 [MEDIUM] CWE-787 CVE-2021-1760: A memory corruption issue was addressed with improved state management. This issue is fixed in macOS
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application could execute arbitrary code leading to compromise of user information.
nvd
CVE-2014-4465P4MEDIUMCVSS 5.0≤ 8.1.22014-12-10
CVE-2014-4465 [MEDIUM] CWE-20 CVE-2014-4465: WebKit in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1 allows remote attackers
WebKit in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1 allows remote attackers to bypass the Same Origin Policy via crafted Cascading Style Sheets (CSS) token sequences within an SVG file in the SRC attribute of an IMG element.
nvd
CVE-2019-8530P4MEDIUMCVSS 5.5fixed in 12.22019-12-18
CVE-2019-8530 [MEDIUM] CVE-2019-8530: This issue was addressed with improved checks. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4
This issue was addressed with improved checks. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2. A malicious application may be able to overwrite arbitrary files.
nvd