cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 156 of 207
CVE-2015-3793P4MEDIUMCVSS 4.3≤ 8.42015-08-17
CVE-2015-3793 [MEDIUM] CWE-264 CVE-2015-3793: CFPreferences in Apple iOS before 8.4.1 allows attackers to bypass the third-party app-sandbox prote CFPreferences in Apple iOS before 8.4.1 allows attackers to bypass the third-party app-sandbox protection mechanism and read arbitrary managed preferences via a crafted app.
nvd
CVE-2015-5749P4MEDIUMCVSS 4.3≤ 8.42015-08-17
CVE-2015-5749 [MEDIUM] CWE-200 CVE-2015-5749: The Sandbox_profiles component in Apple iOS before 8.4.1 allows attackers to bypass the third-party The Sandbox_profiles component in Apple iOS before 8.4.1 allows attackers to bypass the third-party app-sandbox protection mechanism and read arbitrary managed preferences via a crafted app.
nvd
CVE-2025-43434P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43434 [MEDIUM] CWE-416 CVE-2025-43434: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2025-43438P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43438 [MEDIUM] CWE-416 CVE-2025-43438: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2014-4408P4MEDIUMCVSS 6.9≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4408 [MEDIUM] CWE-119 CVE-2014-4408: The rt_setgate function in the kernel in Apple iOS before 8 and Apple TV before 7 allows local users The rt_setgate function in the kernel in Apple iOS before 8 and Apple TV before 7 allows local users to gain privileges or cause a denial of service (out-of-bounds read and device crash) via a crafted call.
nvd
CVE-2016-4781P4MEDIUMCVSS 6.8≤ 10.1.12017-02-20
CVE-2016-4781 [MEDIUM] CWE-254 CVE-2016-4781: An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves t An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "SpringBoard" component, which allows physically proximate attackers to bypass the passcode attempt counter and unlock a device via unspecified vectors.
nvd
CVE-2020-9946P4MEDIUMCVSS 6.8fixed in 14.02020-10-16
CVE-2020-9946 [MEDIUM] CWE-667 CVE-2020-9946: This issue was addressed with improved checks. This issue is fixed in iOS 14.0 and iPadOS 14.0, watc This issue was addressed with improved checks. This issue is fixed in iOS 14.0 and iPadOS 14.0, watchOS 7.0. The screen lock may not engage after the specified time period.
nvd
CVE-2019-8760P4MEDIUMCVSS 6.8fixed in 13.02019-12-18
CVE-2019-8760 [MEDIUM] CWE-287 CVE-2019-8760: This issue was addressed by improving Face ID machine learning models. This issue is fixed in iOS 13 This issue was addressed by improving Face ID machine learning models. This issue is fixed in iOS 13. A 3D model constructed to look like the enrolled user may authenticate via Face ID.
nvd
CVE-2010-3829P4MEDIUMCVSS 5.8≤ 4.1v1.0.0+27 more2010-11-26
CVE-2010-3829 [MEDIUM] CVE-2010-3829: WebKit in Apple iOS before 4.2 allows remote attackers to bypass the remote image loading setting in WebKit in Apple iOS before 4.2 allows remote attackers to bypass the remote image loading setting in Mail via an HTML LINK element with a DNS prefetching property, as demonstrated by an HTML e-mail message that uses a LINK element for X-Confirm-Reading-To functionality, a related issue to CVE-2010-3813.
nvd
CVE-2016-1833P4MEDIUMCVSS 5.5fixed in 9.3.22016-05-20
CVE-2016-1833 [MEDIUM] CWE-125 CVE-2016-1833: The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
nvd
CVE-2016-4618P4MEDIUMCVSS 6.1≤ 9.3.52016-09-25
CVE-2016-4618 [MEDIUM] CWE-79 CVE-2016-4618: Cross-site scripting (XSS) vulnerability in Safari Reader in Apple iOS before 10 and Safari before 1 Cross-site scripting (XSS) vulnerability in Safari Reader in Apple iOS before 10 and Safari before 10 allows remote attackers to inject arbitrary web script or HTML via a crafted web site, aka "Universal XSS (UXSS)."
nvd
CVE-2025-43211P4MEDIUMCVSS 6.2fixed in 18.62025-07-30
CVE-2025-43211 [MEDIUM] CWE-770 CVE-2025-43211: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing web content may lead to a denial-of-service.
nvd
CVE-2026-28822P4MEDIUMCVSS 6.2fixed in 26.42026-03-25
CVE-2026-28822 [MEDIUM] CWE-843 CVE-2026-28822: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An attacker may be able to cause unexpected app termination.
nvd
CVE-2026-20637P4MEDIUMCVSS 6.2fixed in 18.7.7≥ 26.0, < 26.32026-03-25
CVE-2026-20637 [MEDIUM] CWE-416 CVE-2026-20637: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18. A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to cause unexpected system termination.
nvd
CVE-2014-1282P4MEDIUMCVSS 5.8≤ 7.0.6v7.0+5 more2014-03-14
CVE-2014-1282 [MEDIUM] CWE-264 CVE-2014-1282: The Profiles component in Apple iOS before 7.1 and Apple TV before 6.1 allows attackers to bypass in The Profiles component in Apple iOS before 7.1 and Apple TV before 6.1 allows attackers to bypass intended configuration-profile visibility requirements via a long name.
nvd
CVE-2018-4290P4MEDIUMCVSS 5.9fixed in 11.4.12019-04-03
CVE-2018-4290 [MEDIUM] CVE-2018-4290: A denial of service issue was addressed with improved memory handling. This issue affected versions A denial of service issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, watchOS 4.3.2.
nvd
CVE-2020-11762P4MEDIUMCVSS 5.5fixed in 13.62020-04-14
CVE-2020-11762 [MEDIUM] CWE-125 CVE-2020-11762: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaComp An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaCompressor::uncompress in ImfDwaCompressor.cpp when handling the UNKNOWN compression case.
nvd
CVE-2020-11764P4MEDIUMCVSS 5.5fixed in 13.62020-04-14
CVE-2020-11764 [MEDIUM] CWE-787 CVE-2020-11764: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuf An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuffer in ImfMisc.cpp.
nvd
CVE-2014-4354P4MEDIUMCVSS 5.8≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4354 [MEDIUM] CWE-264 CVE-2014-4354: Apple iOS before 8 enables Bluetooth during all upgrade actions, which makes it easier for remote at Apple iOS before 8 enables Bluetooth during all upgrade actions, which makes it easier for remote attackers to bypass intended access restrictions via a Bluetooth session.
nvd
CVE-2019-6231P4MEDIUMCVSS 5.5fixed in 12.1.32019-03-05
CVE-2019-6231 [MEDIUM] CWE-125 CVE-2019-6231: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3 An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to read restricted memory.
nvd
Apple iOS vulnerabilities | cvebase