Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 158 of 207
CVE-2021-30964P4MEDIUMCVSS 5.5fixed in 15.22021-08-24
CVE-2021-30964 [MEDIUM] CWE-732 CVE-2021-30964: An inherited permissions issue was addressed with additional restrictions. This issue is fixed in ma
An inherited permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.1, watchOS 8.3, iOS 15.2 and iPadOS 15.2. A malicious application may be able to bypass Privacy preferences.
nvd
CVE-2020-3875P4MEDIUMCVSS 5.5fixed in 13.3.12020-02-27
CVE-2020-3875 [MEDIUM] CWE-125 CVE-2020-3875: A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.3.1
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to read restricted memory.
nvd
CVE-2020-27946P4MEDIUMCVSS 5.5fixed in 14.32021-04-02
CVE-2020-27946 [MEDIUM] CVE-2020-27946: An information disclosure issue was addressed with improved state management. This issue is fixed in
An information disclosure issue was addressed with improved state management. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a maliciously crafted font may result in the disclosure of process memory.
nvd
CVE-2016-4771P4MEDIUMCVSS 5.5≤ 9.3.52016-09-25
CVE-2016-4771 [MEDIUM] CWE-200 CVE-2016-4771: The kernel in Apple iOS before 10 and OS X before 10.12 allows local users to bypass intended file-a
The kernel in Apple iOS before 10 and OS X before 10.12 allows local users to bypass intended file-access restrictions via a crafted directory pathname.
nvd
CVE-2022-32817P4MEDIUMCVSS 5.5fixed in 15.62022-09-23
CVE-2022-32817 [MEDIUM] CWE-125 CVE-2022-32817: An out-of-bounds read issue was addressed with improved bounds checking. This issue is fixed in watc
An out-of-bounds read issue was addressed with improved bounds checking. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to disclose kernel memory.
nvd
CVE-2018-4431P4MEDIUMCVSS 5.5fixed in 12.1.12019-04-03
CVE-2018-4431 [MEDIUM] CWE-200 CVE-2018-4431: A memory initialization issue was addressed with improved memory handling. This issue affected versi
A memory initialization issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.
nvd
CVE-2021-30867P4MEDIUMCVSS 5.5fixed in 15.02021-08-24
CVE-2021-30867 [MEDIUM] CWE-287 CVE-2021-30867: The issue was addressed with improved authentication. This issue is fixed in iOS 15 and iPadOS 15. A
The issue was addressed with improved authentication. This issue is fixed in iOS 15 and iPadOS 15. A malicious application may be able to access photo metadata without needing permission to access photos.
nvd
CVE-2015-5905P4MEDIUMCVSS 5.0≤ 8.4.12015-09-18
CVE-2015-5905 [MEDIUM] CWE-254 CVE-2015-5905: Safari in Apple iOS before 9 allows remote attackers to spoof the relationship between URLs and web
Safari in Apple iOS before 9 allows remote attackers to spoof the relationship between URLs and web content via a crafted window opener on a web site.
nvd
CVE-2019-8532P4MEDIUMCVSS 5.5fixed in 12.22020-10-27
CVE-2019-8532 [MEDIUM] CVE-2019-8532: A permissions issue was addressed by removing vulnerable code and adding additional checks. This iss
A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in watchOS 5.2, iOS 12.2. A malicious application may be able to access restricted files.
nvd
CVE-2020-29639P4MEDIUMCVSS 5.5fixed in 14.02021-04-02
CVE-2020-29639 [MEDIUM] CWE-125 CVE-2020-29639: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.0
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.0 and iPadOS 14.0. Processing a maliciously crafted font may result in the disclosure of process memory.
nvd
CVE-2020-13631P4MEDIUMCVSS 5.5fixed in 14.02020-05-27
CVE-2020-13631 [MEDIUM] CVE-2020-13631: SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, r
SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.
nvd
CVE-2019-8711P4MEDIUMCVSS 5.3fixed in 13.02019-12-18
CVE-2019-8711 [MEDIUM] CWE-20 CVE-2019-8711: A logic issue existed with the display of notification previews. This issue was addressed with impro
A logic issue existed with the display of notification previews. This issue was addressed with improved validation. This issue is fixed in iOS 13. Notification previews may show on Bluetooth accessories even when previews are disabled.
nvd
CVE-2018-4235P4MEDIUMCVSS 5.5fixed in 11.42018-06-08
CVE-2018-4235 [MEDIUM] CWE-74 CVE-2018-4235: An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Messages" component. It allows local users to perform impersonation attacks via an unspecified injection.
nvd
CVE-2023-42946P4MEDIUMCVSS 5.5fixed in 17.12024-02-21
CVE-2023-42946 [MEDIUM] CVE-2023-42946: This issue was addressed with improved redaction of sensitive information. This issue is fixed in tv
This issue was addressed with improved redaction of sensitive information. This issue is fixed in tvOS 17.1, watchOS 10.1, macOS Sonoma 14.1, iOS 17.1 and iPadOS 17.1. An app may be able to leak sensitive user information.
nvd
CVE-2021-1830P4MEDIUMCVSS 5.5fixed in 14.52021-09-08
CVE-2021-1830 [MEDIUM] CWE-125 CVE-2021-1830: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.5
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.5 and iPadOS 14.5. A local user may be able to read kernel memory.
nvd
CVE-2020-9979P4MEDIUMCVSS 5.5fixed in 14.02020-10-27
CVE-2020-9979 [MEDIUM] CVE-2020-9979: A trust issue was addressed by removing a legacy API. This issue is fixed in iOS 14.0 and iPadOS 14.
A trust issue was addressed by removing a legacy API. This issue is fixed in iOS 14.0 and iPadOS 14.0, tvOS 14.0. An attacker may be able to misuse a trust relationship to download malicious content.
nvd
CVE-2020-9964P4MEDIUMCVSS 5.5fixed in 14.02020-10-16
CVE-2020-9964 [MEDIUM] CWE-665 CVE-2020-9964: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iO
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 14.0 and iPadOS 14.0. A local user may be able to read kernel memory.
nvd
CVE-2017-7140P4MEDIUMCVSS 5.3≤ 10.3.32017-10-23
CVE-2017-7140 [MEDIUM] CWE-200 CVE-2017-7140: An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Keyboard Suggestions" component. It allows attackers to obtain sensitive information by reading keyboard autocorrect suggestions.
nvd
CVE-2022-42843P4MEDIUMCVSS 5.5fixed in 16.22022-12-15
CVE-2022-42843 [MEDIUM] CWE-200 CVE-2022-42843: This issue was addressed with improved data protection. This issue is fixed in iOS 16.2 and iPadOS 1
This issue was addressed with improved data protection. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. A user may be able to view sensitive user information.
nvd
CVE-2023-23499P4MEDIUMCVSS 5.5fixed in 16.32023-02-27
CVE-2023-23499 [MEDIUM] CWE-200 CVE-2023-23499: This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.6.3,
This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13.2, watchOS 9.3, macOS Big Sur 11.7.3, tvOS 16.3, iOS 16.3 and iPadOS 16.3. An app may be able to access user-sensitive data.
nvd