Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 164 of 207
CVE-2015-5820P4MEDIUMCVSS 4.3≤ 8.4.12015-09-18
CVE-2015-5820 [MEDIUM] CWE-20 CVE-2015-5820: WebKit in Apple iOS before 9 allows remote attackers to trigger a dialing action via a crafted (1) t
WebKit in Apple iOS before 9 allows remote attackers to trigger a dialing action via a crafted (1) tel://, (2) facetime://, or (3) facetime-audio:// URL.
nvd
CVE-2022-26764P4MEDIUMCVSS 4.7fixed in 15.52022-05-26
CVE-2022-26764 [MEDIUM] CWE-787 CVE-2022-26764: A memory corruption issue was addressed with improved validation. This issue is fixed in watchOS 8.6
A memory corruption issue was addressed with improved validation. This issue is fixed in watchOS 8.6, tvOS 15.5, macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. An attacker that has already achieved kernel code execution may be able to bypass kernel memory mitigations.
nvd
CVE-2026-28967P4MEDIUMCVSS 4.9fixed in 18.7.7≥ 26.0, < 26.42026-05-11
CVE-2026-28967 [MEDIUM] CWE-400 CVE-2026-28967: A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 1
A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4. An attacker in a privileged network position may be able to cause a denial-of-service.
nvd
CVE-2011-3888P4MEDIUMCVSS 6.8fixed in 5.12011-10-25
CVE-2011-3888 [MEDIUM] CWE-416 CVE-2011-3888: Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows user-assisted remote attack
Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to editing operations in conjunction with an unknown plug-in.
nvd
CVE-2011-1204P4MEDIUMCVSS 6.8fixed in 5.02011-03-11
CVE-2011-1204 [MEDIUM] CWE-20 CVE-2011-1204: Google Chrome before 10.0.648.127 does not properly handle attributes, which allows remote attackers
Google Chrome before 10.0.648.127 does not properly handle attributes, which allows remote attackers to cause a denial of service (DOM tree corruption) or possibly have unspecified other impact via a crafted document.
nvd
CVE-2011-2359P4MEDIUMCVSS 6.8fixed in 5.02011-08-03
CVE-2011-2359 [MEDIUM] CWE-20 CVE-2011-2359: Google Chrome before 13.0.782.107 does not properly track line boxes during rendering, which allows
Google Chrome before 13.0.782.107 does not properly track line boxes during rendering, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-3958P4MEDIUMCVSS 6.8fixed in 6.02012-02-09
CVE-2011-3958 [MEDIUM] CWE-416 CVE-2011-3958: Google Chrome before 17.0.963.46 does not properly perform casts of variables during handling of a c
Google Chrome before 17.0.963.46 does not properly perform casts of variables during handling of a column span, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.
nvd
CVE-2020-3885P4MEDIUMCVSS 4.3fixed in 13.42020-04-01
CVE-2020-3885 [MEDIUM] CWE-670 CVE-2020-3885: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 1
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. A file URL may be incorrectly processed.
nvd
CVE-2015-5838P4MEDIUMCVSS 4.3≤ 8.4.12015-09-18
CVE-2015-5838 [MEDIUM] CWE-284 CVE-2015-5838: SpringBoard in Apple iOS before 9 does not properly restrict access to privileged API calls, which a
SpringBoard in Apple iOS before 9 does not properly restrict access to privileged API calls, which allows attackers to spoof the dialog windows of an arbitrary app via a crafted app.
nvd
CVE-2019-8834P4MEDIUMCVSS 4.3fixed in 13.32020-10-27
CVE-2019-8834 [MEDIUM] CVE-2019-8834: A configuration issue was addressed with additional restrictions. This issue is fixed in tvOS 13.3,
A configuration issue was addressed with additional restrictions. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, iOS 13.3 and iPadOS 13.3, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. An attacker in a privileged network position
nvd
CVE-2025-43445P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43445 [MEDIUM] CWE-125 CVE-2025-43445: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.7.
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process m
nvd
CVE-2025-43384P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43384 [MEDIUM] CWE-125 CVE-2025-43384: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
nvd
CVE-2025-43385P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43385 [MEDIUM] CWE-125 CVE-2025-43385: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
nvd
CVE-2025-43383P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43383 [MEDIUM] CWE-125 CVE-2025-43383: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
nvd
CVE-2025-43441P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43441 [MEDIUM] CWE-119 CVE-2025-43441: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2015-1117P4MEDIUMCVSS 6.9≤ 8.22015-04-10
CVE-2015-1117 [MEDIUM] CWE-264 CVE-2015-1117: The (1) setreuid and (2) setregid system-call implementations in the kernel in Apple iOS before 8.3,
The (1) setreuid and (2) setregid system-call implementations in the kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 do not properly perform privilege drops, which makes it easier for attackers to execute code with unintended user or group privileges via a crafted app.
nvd
CVE-2010-1754P4MEDIUMCVSS 6.9fixed in 4.02010-06-22
CVE-2010-1754 [MEDIUM] CWE-264 CVE-2010-1754: Passcode Lock in Apple iOS before 4 on the iPhone and iPod touch does not properly handle alert-base
Passcode Lock in Apple iOS before 4 on the iPhone and iPod touch does not properly handle alert-based unlocks in conjunction with subsequent Remote Lock operations through MobileMe, which allows physically proximate attackers to bypass intended passcode requirements via unspecified vectors.
nvd
CVE-2012-3728P4MEDIUMCVSS 6.9≤ 5.1.1v1.0.0+38 more2012-09-20
CVE-2012-3728 [MEDIUM] CWE-264 CVE-2012-3728: The kernel in Apple iOS before 6 dereferences invalid pointers during the handling of packet-filter
The kernel in Apple iOS before 6 dereferences invalid pointers during the handling of packet-filter data structures, which allows local users to gain privileges via a crafted program that makes packet-filter ioctl calls.
nvd
CVE-2011-2391P4MEDIUMCVSS 6.1≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2011-2391 [MEDIUM] CWE-20 CVE-2011-2391: The IPv6 implementation in the kernel in Apple iOS before 7 allows remote attackers to cause a denia
The IPv6 implementation in the kernel in Apple iOS before 7 allows remote attackers to cause a denial of service (CPU consumption) via crafted ICMPv6 packets.
nvd
CVE-2023-32371P4MEDIUMCVSS 6.3fixed in 16.52023-06-23
CVE-2023-32371 [MEDIUM] CVE-2023-32371: The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, macOS
The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, macOS Ventura 13.4. An app may be able to break out of its sandbox.
nvd