Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 143 of 207
CVE-2025-24198P4MEDIUMCVSS 6.6fixed in 18.42025-03-31
CVE-2025-24198 [MEDIUM] CWE-284 CVE-2025-24198: This issue was addressed by restricting options offered on a locked device. This issue is fixed in i
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker with physical access may be able to use Siri to access sensitive user data.
nvd
CVE-2018-4305P4MEDIUMCVSS 6.5fixed in 12.02019-04-03
CVE-2018-4305 [MEDIUM] CWE-20 CVE-2018-4305: An input validation issue was addressed with improved input validation. This issue affected versions
An input validation issue was addressed with improved input validation. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5.
nvd
CVE-2021-30866P4MEDIUMCVSS 6.5fixed in 15.02021-08-24
CVE-2021-30866 [MEDIUM] CVE-2021-30866: A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in tvO
A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. A device may be passively tracked by its WiFi MAC address.
nvd
CVE-2025-30445P4MEDIUMCVSS 6.5fixed in 18.42025-04-29
CVE-2025-30445 [MEDIUM] CWE-843 CVE-2025-30445: A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadO
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4. An attacker on the local network may cause an unexpected app termination.
nvd
CVE-2025-31203P4MEDIUMCVSS 6.5fixed in 18.42025-04-29
CVE-2025-31203 [MEDIUM] CWE-190 CVE-2025-31203: An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.4 an
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An attacker on the local network may be able to cause a denial-of-service.
nvd
CVE-2021-30714P4MEDIUMCVSS 6.3fixed in 14.62021-09-08
CVE-2021-30714 [MEDIUM] CWE-362 CVE-2021-30714: A race condition was addressed with improved state handling. This issue is fixed in iOS 14.6 and iPa
A race condition was addressed with improved state handling. This issue is fixed in iOS 14.6 and iPadOS 14.6. An application may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2017-7109P4MEDIUMCVSS 6.1≤ 10.3.32017-10-23
CVE-2017-7109 [MEDIUM] CWE-79 CVE-2017-7109: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. A cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web
nvd
CVE-2024-54523P4MEDIUMCVSS 6.3fixed in 18.22025-01-27
CVE-2024-54523 [MEDIUM] CWE-787 CVE-2024-54523: The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.2 and iPadOS 18.2
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, watchOS 11.2. An app may be able to corrupt coprocessor memory.
nvd
CVE-2017-7059P4MEDIUMCVSS 6.1fixed in 10.3.32017-07-20
CVE-2017-7059 [MEDIUM] CWE-79 CVE-2017-7059: A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safar
A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component.
nvd
CVE-2016-4741P4MEDIUMCVSS 5.9≤ 9.3.52016-09-18
CVE-2016-4741 [MEDIUM] CWE-254 CVE-2016-4741: The Assets component in Apple iOS before 10 allows man-in-the-middle attackers to block software upd
The Assets component in Apple iOS before 10 allows man-in-the-middle attackers to block software updates via vectors related to lack of an HTTPS session for retrieving updates.
nvd
CVE-2022-32891P4MEDIUMCVSS 6.1fixed in 16.02023-02-27
CVE-2022-32891 [MEDIUM] CWE-1021 CVE-2022-32891: The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchO
The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchOS 9, iOS 16. Visiting a website that frames malicious content may lead to UI spoofing.
nvd
CVE-2026-28833P4MEDIUMCVSS 6.2fixed in 26.42026-03-25
CVE-2026-28833 [MEDIUM] CWE-284 CVE-2026-28833: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.4 and
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. An app may be able to enumerate a user's installed apps.
nvd
CVE-2026-28897P4MEDIUMCVSS 6.2fixed in 18.7.9≥ 26.0, < 26.52026-05-11
CVE-2026-28897 [MEDIUM] CWE-121 CVE-2026-28897: A buffer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 an
A buffer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A local user may be able to cause unexpected system termination or read kernel memory.
nvd
CVE-2014-1285P4MEDIUMCVSS 5.8≤ 7.0.6v7.0+5 more2014-03-14
CVE-2014-1285 [MEDIUM] CWE-264 CVE-2014-1285: Springboard in Apple iOS before 7.1 allows physically proximate attackers to bypass intended access
Springboard in Apple iOS before 7.1 allows physically proximate attackers to bypass intended access restrictions and read the home screen by leveraging an application crash during activation of an unactivated device.
nvd
CVE-2026-43666P4MEDIUMCVSS 6.2fixed in 18.7.9≥ 26.0, < 26.52026-05-11
CVE-2026-43666 [MEDIUM] CWE-787 CVE-2026-43666: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An attacker on the local network may be able to cause a denial-of-service.
nvd
CVE-2022-22652P4MEDIUMCVSS 6.1fixed in 15.42022-03-18
CVE-2022-22652 [MEDIUM] CWE-306 CVE-2022-22652: The GSMA authentication panel could be presented on the lock screen. The issue was resolved by requi
The GSMA authentication panel could be presented on the lock screen. The issue was resolved by requiring device unlock to interact with the GSMA authentication panel. This issue is fixed in iOS 15.4 and iPadOS 15.4. A person with physical access may be able to view and modify the carrier account information and settings from the lock screen.
nvd
CVE-2017-2411P4MEDIUMCVSS 5.9fixed in 11.22019-01-11
CVE-2017-2411 [MEDIUM] CWE-254 CVE-2017-2411: In iOS before 11.2, exchange rates were retrieved from HTTP rather than HTTPS. This was addressed by
In iOS before 11.2, exchange rates were retrieved from HTTP rather than HTTPS. This was addressed by enabling HTTPS for exchange rates.
nvd
CVE-2024-44145P4MEDIUMCVSS 6.1fixed in 18.02024-10-28
CVE-2024-44145 [MEDIUM] CVE-2024-44145: This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS
This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An attacker with physical access to a macOS device with Sidecar enabled may be able to bypass the Lock Screen.
nvd
CVE-2021-30682P4MEDIUMCVSS 5.5fixed in 14.62021-09-08
CVE-2021-30682 [MEDIUM] CVE-2021-30682: A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 a
A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. A malicious application may be able to leak sensitive user information.
nvd
CVE-2019-8540P4MEDIUMCVSS 5.5fixed in 12.22019-12-18
CVE-2019-8540 [MEDIUM] CWE-665 CVE-2019-8540: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iO
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to determine kernel memory layout.
nvd