Apple iOS vulnerabilities
4,109 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,109
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL335HIGH1680MEDIUM1805LOW289
Vulnerabilities
Page 16 of 206
CVE-2019-6205P3HIGHCVSS 7.8PoCfixed in 12.1.32019-03-05
CVE-2019-6205 [HIGH] CWE-787 CVE-2019-6205: A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iO
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A malicious application may cause unexpected changes in memory shared between processes.
nvd
CVE-2017-2442P3MEDIUMCVSS 6.5PoC≤ 10.2.12017-04-02
CVE-2017-2442 [MEDIUM] CWE-20 CVE-2017-2442: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit JavaScript Bindings" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
nvd
CVE-2017-2480P3MEDIUMCVSS 6.5PoC≤ 10.2.12017-04-02
CVE-2017-2480 [MEDIUM] CWE-200 CVE-2017-2480: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affected. iTunes before 12.6 on Windows is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive in
nvd
CVE-2018-4384P3HIGHCVSS 7.8PoCfixed in 12.12019-04-03
CVE-2018-4384 [HIGH] CWE-119 CVE-2018-4384: A memory corruption issue was addressed with improved input validation. This issue affected versions
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1, watchOS 5.1.
nvd
CVE-2019-8600P2CRITICALCVSS 9.8fixed in 12.32019-12-18
CVE-2019-8600 [CRITICAL] CWE-89 CVE-2019-8600: A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 1
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. A maliciously crafted SQL query may lead to arbitrary code execution.
nvd
CVE-2019-8718P3HIGHCVSS 7.8PoCfixed in 13.02020-10-27
CVE-2019-8718 [HIGH] CWE-787 CVE-2019-8718: A memory corruption issue was addressed with improved memory handling. This issue is fixed in watchO
A memory corruption issue was addressed with improved memory handling. This issue is fixed in watchOS 6, iOS 13, tvOS 13. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2012-2619P3HIGHCVSS 7.8PoC≤ 6.0.2v6.0+1 more2012-11-14
CVE-2012-2619 [HIGH] CWE-20 CVE-2012-2619: The Broadcom BCM4325 and BCM4329 Wi-Fi chips, as used in certain Acer, Apple, Asus, Ford, HTC, Kyoce
The Broadcom BCM4325 and BCM4329 Wi-Fi chips, as used in certain Acer, Apple, Asus, Ford, HTC, Kyocera, LG, Malata, Motorola, Nokia, Pantech, Samsung, and Sony products, allow remote attackers to cause a denial of service (out-of-bounds read and Wi-Fi outage) via an RSN 802.11i information element.
nvd
CVE-2018-4435P3HIGHCVSS 7.8PoCfixed in 12.1.12019-04-03
CVE-2018-4435 [HIGH] CWE-20 CVE-2018-4435: A logic issue was addressed with improved restrictions. This issue affected versions prior to iOS 12
A logic issue was addressed with improved restrictions. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.
nvd
CVE-2017-2478P3HIGHCVSS 7.0PoC≤ 10.2.12017-04-02
CVE-2017-2478 [HIGH] CWE-362 CVE-2017-2478: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2016-1719P3HIGHCVSS 7.8PoC≤ 9.22016-02-01
CVE-2016-1719 [HIGH] CWE-119 CVE-2016-1719: The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows loc
The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2019-8649P3MEDIUMCVSS 6.1PoCfixed in 12.42019-12-18
CVE-2019-8649 [MEDIUM] CWE-79 CVE-2019-8649: A logic issue existed in the handling of synchronous page loads. This issue was addressed with impro
A logic issue existed in the handling of synchronous page loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to universal cross sit
nvd
CVE-2015-6996P3MEDIUMCVSS 6.8PoC≤ 9.0.22015-10-23
CVE-2015-6996 [MEDIUM] CWE-119 CVE-2015-6996: IOAcceleratorFamily in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows at
IOAcceleratorFamily in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2015-7068P3HIGHCVSS 7.8PoCfixed in 9.22015-12-11
CVE-2015-7068 [HIGH] CWE-476 CVE-2015-7068: IOKit SCSI in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 all
IOKit SCSI in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via an app that provides an unspecified userclient type.
nvd
CVE-2015-6995P3MEDIUMCVSS 6.8PoC≤ 9.0.22015-10-23
CVE-2015-6995 [MEDIUM] CWE-119 CVE-2015-6995: The Disk Images component in Apple iOS before 9.1 and OS X before 10.11.1 misparses images, which al
The Disk Images component in Apple iOS before 9.1 and OS X before 10.11.1 misparses images, which allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2018-4240P3MEDIUMCVSS 6.5PoCfixed in 11.42018-06-08
CVE-2018-4240 [MEDIUM] CWE-20 CVE-2018-4240: An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Messages" component. It allows remote attackers to cause a denial of service via a crafted message.
nvd
CVE-2022-37434P2CRITICALCVSS 9.8fixed in 15.7.1≥ 16.0, < 16.12022-08-05
CVE-2022-37434 [CRITICAL] CWE-787 CVE-2022-37434: zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).
nvd
CVE-2017-2456P3HIGHCVSS 7.0PoC≤ 10.2.12017-04-02
CVE-2017-2456 [HIGH] CWE-362 CVE-2017-2456: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2017-2501P3HIGHCVSS 7.0PoCfixed in 10.3.22017-05-22
CVE-2017-2501 [HIGH] CWE-362 CVE-2017-2501: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "Kernel" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2018-4280P3HIGHCVSS 7.8PoCfixed in 11.4.12019-04-03
CVE-2018-4280 [HIGH] CWE-119 CVE-2018-4280: A memory corruption issue was addressed with improved memory handling. This issue affected versions
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2.
nvd
CVE-2016-7621P3HIGHCVSS 7.8PoC≤ 10.1.12017-02-20
CVE-2016-7621 [HIGH] CWE-416 CVE-2016-7621: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows local users to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via unspecified vectors.
nvd